QID 38917
QID 38917: OpenSSL OpenSSL Security Update
The OpenSSL Project is an Open Source toolkit implementing the Secure Sockets Layer (SSL v2/v3) and Transport Layer Security (TLS) protocols as well as a general-purpose cryptography library.
Applications that use the function EVP_PKEY_public_check() to check RSA public keys may experience long delays. Where the key that is being checked has been obtained from an untrusted source this may lead to a Denial of Service.
Affected Versions:
From 3.0.0 and before 3.0.13.
From 3.1.0 and before 3.1.5.
From 3.2.0 and before 3.2.1.
Successful exploitation of this vulnerability may allow a remote attacker to cause Denial of Service.
Solution
Please refer OpenSSL Advisory to obtain more information.
Vendor References
- OpenSSL Advisory -
www.openssl.org/news/secadv/20240115.txt
CVEs related to QID 38917
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| OpenSSL Advisory |
|