CVE Database
/

CVE-2017-3730

Back to search

CVE-2017-3730

Published: May 4, 2017

Modified: Sep 16, 2024

PUBLISHED

Description

In OpenSSL 1.1.0 before 1.1.0d, if a malicious server supplies bad parameters for a DHE or ECDHE key exchange then this can result in the client attempting to dereference a NULL pointer leading to a client crash. This could be exploited in a Denial of Service attack.

VendorProductVersions

OpenSSL

OpenSSL

affected
openssl-1.1.0
affected
openssl-1.1.0a
affected
openssl-1.1.0b
affected
openssl-1.1.0c

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now