Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:3474
HistoryFeb 07, 2017 - 1:12 a.m.

Information Disclosure

2017-02-0701:12:09
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
17

EPSS

0.009

Percentile

83.1%

OpenSSL is vulnerable to information disclosure. When pretty printing through the OBJ_obj2txt function in crypto/objects/obj_dat.c is it possible for attackers to read from the process stack memory. This is caused because OpenSSL does not ensure the presence of \0 characters.

References