Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:3566
HistoryFeb 10, 2017 - 5:44 a.m.

Denial Of Service (DoS) Through An Infinite Loop

2017-02-1005:44:00
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
30

EPSS

0.567

Percentile

97.7%

OpenSSL is vulnerable to denial of service (DoS) attacks. These attacks are possible because it does not correctly handle ECParameter structures where the curve is over a malformed binary polynomial field. These attacks can be triggered through a session that uses an Elliptic Curve algorithm.

References