Back

HIGH

ChaCha20/Poly1305 heap-buffer-overflow

Published May 4, 2017

Description

In OpenSSL 1.1.0 before 1.1.0c, TLS connections using *-CHACHA20-POLY1305 ciphersuites are susceptible to a DoS attack by corrupting larger payloads. This can result in an OpenSSL crash. This issue is not considered to be exploitable beyond a DoS.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (2)

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner openssl
Published May 4, 2017
Updated Sep 17, 2024
Reserved Aug 23, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Nov 10, 2016