Description
Constructed ASN.1 types with a recursive definition (such as can be found in PKCS7) could eventually exceed the stack given malicious input with excessive recursion. This could result in a Denial Of Service attack. There are no such structures used within SSL/TLS that come from untrusted sources so this is considered safe. Fixed in OpenSSL 1.1.0h (Affected 1.1.0-1.1.0g). Fixed in OpenSSL 1.0.2o (Affected 1.0.2b-1.0.2n).
Remediation
References
Related Vulnerabilities
WordPress Denial of Service Vulnerability (3.5 - 3.6.1)
MySQL Resource Management Errors Vulnerability (CVE-2010-3837)
Envoy Proxy Use After Free Vulnerability (CVE-2026-47205)
WebLogic CVE-2018-2935 Vulnerability (CVE-2018-2935)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-4297)