The state-machine implementation in OpenSSL 1.1.0 before 1.1.0a allocates memory before checking for an excessive length, which might allow remote attackers to cause a denial of service (memory consumption) via crafted TLS messages, related to statem/statem.c and statem/statem_lib.c.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Cisco Anyconnect | — | Upgrade to the latest version of Cisco Secure Client to resolve this vulnerability. | Dec 16, 2020 | Sep 26, 2016 |
| Freebsd | — | Upgrade opensslUpgrade FreeBSDUpgrade linux-c6-opensslUpgrade openssl-devel | Nov 14, 2016 | Sep 22, 2016 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | Sep 26, 2016 | Sep 26, 2016 |
| Huawei Vrp | — | Contact Huawei TAC to request the upgrades | Apr 2, 2026 | Mar 22, 2017 |
| Oracle Solaris | — | Upgrade library/security/openssl/openssl-fips-140 to version 2.0.6-0.175.3.13.0.4.0 on Solaris 11.3Upgrade library/security/openssl to version 1.0.1.21-0.175.3.13.0.4.0 on Solaris 11.3 | May 29, 2017 | Sep 26, 2016 |
| Pulse Secure Pulse Connect Secure | — | Update Pulse Connect Secure to version 8.2R6Update Pulse Connect Secure to version 8.1R11.1Update Pulse Connect Secure to version 8.1R11 | Oct 28, 2020 | Sep 26, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub