Malformed SHA512 ticket DoS (CVE-2016-6302)
Low
Vulnerability Details
If a server uses SHA512 for TLS session ticket HMAC it is vulnerable to a
DoS attack where a malformed ticket will result in an OOB read which will
ultimately crash.
The use of SHA512 in TLS session tickets is comparatively rare as it requires
a custom server callback and ticket lookup mechanism.
refer:
https://www.openssl.org/news/secadv/20160922.txt
Actions
View on HackerOneReport Stats
- Report ID: 221787
- State: Closed
- Substate: resolved
- Upvotes: 7