CVE Database
/

CVE-2017-3731

Back to search

CVE-2017-3731

Published: May 4, 2017

Modified: Sep 16, 2024

PUBLISHED

Description

If an SSL/TLS server or client is running on a 32-bit host, and a specific cipher is being used, then a truncated packet can cause that server or client to perform an out-of-bounds read, usually resulting in a crash. For OpenSSL 1.1.0, the crash can be triggered when using CHACHA20/POLY1305; users should upgrade to 1.1.0d. For Openssl 1.0.2, the crash can be triggered when using RC4-MD5; users who have not disabled that algorithm should update to 1.0.2k.

VendorProductVersions

OpenSSL

OpenSSL

affected
openssl-1.1.0
affected
openssl-1.1.0a
affected
openssl-1.1.0b
affected
openssl-1.1.0c
affected
openssl-1.0.2

+10 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now