OpenSSL.CMS.Structure.Null.Pointer.Dereference
Description
This indicates an attack attempt against a Memory Corruption vulnerability in the OpenSSL library.
The vulnerability is caused by an error when the the software attempts to handle a specially crafted CMS (Cryptographic Message Syntax) structure. A remote attacker can exploit this to cause a denial of service condition on vulnerable systems.
Affected Products
OpenSSL 1.1
OpenSSL 1.1.0a
OpenSSL 1.1.0b
Impact
Denial of Service: Remote attackers can crash vulnerable systems.
Recommended Actions
Apply the most recent upgrade or patch from the vendor.
https://www.openssl.org/news/secadv/20161110.txt
Telemetry
Coverage
IPS (Regular DB) | |
IPS (Extended DB) |
Version Updates
Date | Version | Detail |
---|---|---|
2019-11-22 | 15.729 | Name:Openssl. CMS. Structure. Null. dereference:OpenSSL. CMS. Structure. Null. Pointer. Dereference |