Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:3473
HistoryFeb 07, 2017 - 1:07 a.m.

Denial Of Service (DoS) Through Memory Overwrite

2017-02-0701:07:14
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
15

0.024 Low

EPSS

Percentile

90.0%

OepnSSL is vulnerable to denial of service (DoS) attacks through memory overwrite and client application crash. If a multithreaded client connects to a malicious server using a resumed session, it is possible to trigger a race condition in the ssl_parse_serverhello_tlsext function which allows an attacker to write up to 255 bytes of freed memory.

References