Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:3334
HistoryJan 26, 2017 - 3:18 a.m.

Denial Of Service (DoS)

2017-01-2603:18:38
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13

EPSS

0.293

Percentile

96.9%

OpenSSL is vulnerable to Denial of Service (DoS) attacks. A malicious user can crash the server by passing a malformed SHA512 TLS session ticket HMAC to the server, resulting in an out-of-bounds read which ultimately will result in crashing the server.

References