[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS-2021-1541 --- openssl

ID: oval:org.secpod.oval:def:1601474Date: (C)2021-10-06   (M)2023-11-10
Class: PATCHFamily: unix




It was found that openssl assumed ASN.1 strings to be NUL terminated. A malicious actor may be able to force an application into calling openssl function with a specially crafted, non-NUL terminated string to deliberately hit this bug, which may result in a crash of the application, causing a Denial of Service attack, or possibly, memory disclosure. The highest threat from this vulnerability is to data confidentiality and system availability

Platform:
Amazon Linux AMI
Product:
openssl
Reference:
ALAS-2021-1541
CVE-2021-3712
CVE    1
CVE-2021-3712

© SecPod Technologies