Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:3426
HistoryFeb 03, 2017 - 6:21 a.m.

Denial Of Service (DoS)

2017-02-0306:21:34
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
21

EPSS

0.405

Percentile

97.3%

OpenSSL is vulnerable to denial of service (DoS) attacks. The library does not clear DTLS handshake messages when they are delivered out of order even when the handshake has been completed. A malicious user can take advantage of this by opening multiple DTLS connections to the system, causing a denial of service via memory consumption.

References