Malformed SHA512 ticket DoS (CVE-2016-6302)

Disclosed: 2017-05-25 01:33:01 By theyarestone To ibb
Low
Vulnerability Details
If a server uses SHA512 for TLS session ticket HMAC it is vulnerable to a DoS attack where a malformed ticket will result in an OOB read which will ultimately crash. The use of SHA512 in TLS session tickets is comparatively rare as it requires a custom server callback and ticket lookup mechanism. refer: https://www.openssl.org/news/secadv/20160922.txt
Actions
View on HackerOne
Report Stats
  • Report ID: 221787
  • State: Closed
  • Substate: resolved
  • Upvotes: 7
Share this report