Record summary

CVE-2016-7054 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit.

Description

In OpenSSL 1.1.0 before 1.1.0c, TLS connections using *-CHACHA20-POLY1305 ciphersuites are susceptible to a DoS attack by corrupting larger payloads. This can result in an OpenSSL crash. This issue is not considered to be exploitable beyond a DoS.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE Listopenssl-1.1.0affected
openssl-1.1.0aaffected
openssl-1.1.0baffected

Proofs of concept

1

Catalogued exploits

ExploitDBOpenSSL 1.1.0a/1.1.0b - Denial of ServiceExploitDB exploitby SilverfoxNot analyzed1 file
ExploitDB

PoC details

References

6