In OpenSSL 1.1.0 before 1.1.0c, TLS connections using *-CHACHA20-POLY1305 ciphersuites are susceptible to a DoS attack by corrupting larger payloads. This can result in an OpenSSL crash. This issue is not considered to be exploitable beyond a DoS.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2017-05-04 19:29
Updated : 2025-04-20 01:37
NVD link : CVE-2016-7054
Mitre link : CVE-2016-7054
CVE.ORG link : CVE-2016-7054
JSON object : View
Products Affected
openssl
- openssl
CWE
CWE-284
Improper Access Control