Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:13389
HistoryMar 01, 2019 - 1:32 a.m.

Padding Oracle Attack

2019-03-0101:32:23
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14

0.01 Low

EPSS

Percentile

83.9%

openssl is vulnerable to padding oracle attacks. In the event of a fatal protocol error and SSL_shutdown() is called twice, an attacker is able to perform a padding oracle attack to decrypt data by sending a 0 byte record with invalid padding, causing the application to behave differently due to various error codes. The attack will then be successful if the attacker is able to detect these application behaviors.

References