Lucene search

K
prionPRIOn knowledge basePRION:CVE-2017-3733
HistoryMay 04, 2017 - 7:29 p.m.

Design/Logic Flaw

2017-05-0419:29:00
PRIOn knowledge base
www.prio-n.com
6

7.2 High

AI Score

Confidence

High

0.036 Low

EPSS

Percentile

91.7%

During a renegotiation handshake if the Encrypt-Then-Mac extension is negotiated where it was not in the original handshake (or vice-versa) then this can cause OpenSSL 1.1.0 before 1.1.0e to crash (dependent on ciphersuite). Both clients and servers are affected.