Lucene search

K
osvGoogleOSV:CVE-2021-41581
HistorySep 24, 2021 - 3:15 a.m.

CVE-2021-41581

2021-09-2403:15:06
Google
osv.dev
4
cve-2021-41581
libressl
stack-based
buffer over-read
x509_constraints_parse_mailbox
domain_part_max_len
input exceeds

AI Score

7

Confidence

High

EPSS

0.001

Percentile

23.5%

x509_constraints_parse_mailbox in lib/libcrypto/x509/x509_constraints.c in LibreSSL through 3.4.0 has a stack-based buffer over-read. When the input exceeds DOMAIN_PART_MAX_LEN, the buffer lacks ‘\0’ termination.

AI Score

7

Confidence

High

EPSS

0.001

Percentile

23.5%

Related for OSV:CVE-2021-41581