Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:3451
HistoryFeb 06, 2017 - 5:19 a.m.

Denial Of Service (DoS) Through Memory Consumption And Application Crash

2017-02-0605:19:25
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14

0.05 Low

EPSS

Percentile

92.9%

OpenSSL is vulnerable to denial of service (DoS) attacks through memory consumption and application crash. This is caused because the dtls1_clear_queues function in d1_lib.c frees data not taking into account that application data could arrive between the ChangeCipherSpec message and the Finished message. This can cause the DTLS peer to buffer the application data and cause a segmentation fault.

References