Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:3350
HistoryJan 27, 2017 - 5:17 a.m.

Buffer Overflow

2017-01-2705:17:12
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
28

0.328 Low

EPSS

Percentile

97.1%

OpenSSL is vulnerable to buffer overflow. A malicious user can pass a large amount of data to the EVP_EncryptUpdate() function after calling that function previously with a partial block can cause the length check to overflow. This can be used to crash the application.

References