Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:3342
HistoryJan 26, 2017 - 7:46 a.m.

Denial Of Service (DoS) In SSL Alert Handling

2017-01-2607:46:58
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
23

0.202 Low

EPSS

Percentile

96.4%

OpenSSL is vulnerable to denial of service in SSL alert handling (aka) SSL-Death-Alert. The attacks are possible due to a flaw in the way SSL3_AL_WARNING are handled, consuming 100% CPU on the server.

References