Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:12329
HistoryJan 15, 2019 - 9:15 a.m.

Denial Of Service (DoS) In SSL Alert Handling

2019-01-1509:15:53
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
21

EPSS

0.27

Percentile

96.9%

OpenSSL is vulnerable to denial of service in SSL alert handling (aka) SSL-Death-Alert. The attacks are possible due to a flaw in the way SSL3_AL_WARNING are handled, consuming 100% CPU on the server.

References