Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:11693
HistoryJan 15, 2019 - 9:06 a.m.

Denial Of Service (DoS) Through Memory Consumption And Application Crash

2019-01-1509:06:14
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14

EPSS

0.04

Percentile

92.1%

OpenSSL is vulnerable to denial of service (DoS). It is possible due to not properly handling application data in the dtls1_clear_queues function in d1_lib.c. allowing the data to arrive between the ChangeCipherSpec message and the Finished message and subsequently allowing DTLS peer to buffer the data and cause a segmentation fault.

References