Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:24138
HistoryApr 10, 2020 - 12:47 a.m.

Denial Of Service (DoS)

2020-04-1000:47:06
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
17

0.204 Low

EPSS

Percentile

96.4%

OpenSSL is vulnerable to denial of service. It was found that the OpenSSL library did not properly re-initialize its internal state in the SSL_library_init() function after previous calls to the CRYPTO_cleanup_all_ex_data() function, which would cause a memory leak for each subsequent SSL connection. This flaw could cause server applications that call those functions during reload, such as a combination of the Apache HTTP Server, mod_ssl, PHP, and cURL, to consume all available memory, resulting in a denial of service.

References