Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
ssl/t1_lib.c in OpenSSL 0.9.8h through 0.9.8q and 1.0.0 through 1.0.0c allows remote attackers to cause a denial of service (crash), and possibly obtain sensitive information in applications that use OpenSSL, via a malformed ClientHello handshake message that triggers an out-of-bounds memory access, aka "OCSP stapling vulnerability."
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
OpenSSL ssl/t1_lib.c文件敏感信息泄露漏洞
Vulnerability Description
OpenSSL 是一种开放源码的SSL实现,用来实现网络通信的高强度加密,现在被广泛地用于各种网络应用程序中。 OpenSSL 0.9.8h至0.9.8q版本和1.0.0至1.0.0c版本中的ssl/t1_lib.c文件中存在资源管理错误漏洞。远程攻击者可以借助触发了越界内存访问的畸形ClientHello握手消息导致拒绝服务(崩溃),并可能在使用OpenSSL的应用程序中获取敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A