CVE Database
/

CVE-2016-7054

Back to search

CVE-2016-7054

Published: May 4, 2017

Modified: Sep 17, 2024

PUBLISHED

Description

In OpenSSL 1.1.0 before 1.1.0c, TLS connections using *-CHACHA20-POLY1305 ciphersuites are susceptible to a DoS attack by corrupting larger payloads. This can result in an OpenSSL crash. This issue is not considered to be exploitable beyond a DoS.

VendorProductVersions

OpenSSL

OpenSSL

affected
openssl-1.1.0
affected
openssl-1.1.0a
affected
openssl-1.1.0b

References

94238
vdb-entry
x_refsource_BID
40899
exploit
x_refsource_EXPLOIT-DB
1037261
vdb-entry
x_refsource_SECTRACK

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now