The ssl3_read_bytes function in record/rec_layer_s3.c in OpenSSL 1.1.0 before 1.1.0a allows remote attackers to cause a denial of service (infinite loop) by triggering a zero-length record in an SSL_peek call.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Cisco Anyconnect | — | Upgrade to the latest version of Cisco Secure Client to resolve this vulnerability. | Dec 16, 2020 | Sep 26, 2016 |
| Freebsd | — | Upgrade linux-c6-opensslUpgrade opensslUpgrade openssl-develUpgrade FreeBSD | Nov 14, 2016 | Sep 22, 2016 |
| Gentoo Linux | — | Upgrade dev-libs/openssl. | Oct 30, 2017 | Sep 26, 2016 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | Sep 26, 2016 | Sep 26, 2016 |
| Huawei Vrp | — | Contact Huawei TAC to request the upgrades | Apr 2, 2026 | Mar 22, 2017 |
| Oracle Solaris | — | Upgrade library/security/openssl to version 1.0.1.21-0.175.3.13.0.4.0 on Solaris 11.3Upgrade library/security/openssl/openssl-fips-140 to version 2.0.6-0.175.3.13.0.4.0 on Solaris 11.3 | May 29, 2017 | Sep 26, 2016 |
| Pulse Secure Pulse Connect Secure | — | Update Pulse Connect Secure to version 8.2R6Update Pulse Connect Secure to version 8.1R11.1Update Pulse Connect Secure to version 8.1R11 | Oct 28, 2020 | Sep 26, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub