Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:3347
HistoryJan 27, 2017 - 3:10 a.m.

Padding Oracle Attack

2017-01-2703:10:31
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
38

0.967 High

EPSS

Percentile

99.7%

OpenSSL is vulnerable to padding oracle attacks. The library does not check if there is enough data in both the MAC hash and padding bytes, allowing an attacker to recover the plain text by using the server as a padding oracle. Note: This vulnerability exists because of an incorrect fix for CVE-2013-0169.

References