Lack of data validation In openssl
Description
A flaw was found in OpenSSL. When an application uses the X509_VERIFY_PARAM_set1_email() function to validate a specially crafted S/MIME (Secure/Multipurpose Internet Mail Extensions) email address, an out-of-bounds read can occur. A remote attacker could exploit this vulnerability by sending a malicious email, leading to an application crash and a Denial of Service (DoS). This issue does not directly expose sensitive data.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component |
|---|---|
rpm rhel8 | |
rpm rhel8 | |
rpm rhel8 | |
rpm rhel9 | |
rpm rhel10 | |
rpm rhel7 | |
rpm rhel8 | |
rpm rhel9 | |
rpm rhel9 | |
rpm rhel8 |
1-10 of 18
10
Aliases
1. 2. 3.