Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39192
HistoryFeb 10, 2023 - 4:58 a.m.

Buffer Overflow

2023-02-1004:58:21
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
21
openssl
buffer overflow
x.509 certificate

EPSS

0.001

Percentile

32.4%

openssl is vulnerable to buffer overflow. The vulnerability exists because a buffer overrun can be be triggered in X.509 certificate verification, specifically in name constraint checking where this occurs after certificate chain signature verification and requires either a CA to have signed the malicious certificate or for the application to continue certificate verification despite failure to construct a path to a trusted issuer.