Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:11949
HistoryJan 15, 2019 - 9:10 a.m.

Denial Of Service (DoS)

2019-01-1509:10:17
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13

0.476 Medium

EPSS

Percentile

97.5%

OpenSSL is vulnerable to denial of service attacks. The attacks are due to a flaw in the way OpenSSL does the SSLv2 handshake messages. Therefore, when it has SSLv2 and EXPORT-grade cipher suites enabled, attackers can send malicious SSLv2 CLIENT-MASTER-Key messages to cause server failures.

References