Description
In OpenSSL 1.1.0 before 1.1.0c, TLS connections using *-CHACHA20-POLY1305 ciphersuites are susceptible to a DoS attack by corrupting larger payloads. This can result in an OpenSSL crash. This issue is not considered to be exploitable beyond a DoS.
Exploits (1)
References (5)
Scores
CVSS v3
7.5
EPSS
0.2094
EPSS Percentile
95.7%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-284
Status
published
Products (6)
openssl/openssl
1.1.0
openssl/openssl
1.1.0a
openssl/openssl
1.1.0b
OpenSSL/OpenSSL
openssl-1.1.0
OpenSSL/OpenSSL
openssl-1.1.0a
OpenSSL/OpenSSL
openssl-1.1.0b
Published
May 04, 2017
Tracked Since
Feb 18, 2026