Description
OpenSSL 0.9.6 and 0.9.7 does not properly track the number of characters in certain ASN.1 inputs, which allows remote attackers to cause a denial of service (crash) via an SSL client certificate that causes OpenSSL to read past the end of a buffer when the long form is used.
Remediation
References
Related Vulnerabilities
Sqlite Use After Free Vulnerability (CVE-2020-13630)
WordPress Plugin WordPress Page Contact SQL Injection (1.0)
Plone CMS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-4042)
WebLogic CVE-2019-2568 Vulnerability (CVE-2019-2568)
Jenkins 7PK - Security Features Vulnerability (CVE-2014-9635)