Description
statem/statem.c in OpenSSL 1.1.0a does not consider memory-block movement after a realloc call, which allows remote attackers to cause a denial of service (use-after-free) or possibly execute arbitrary code via a crafted TLS session.
Remediation
References
Related Vulnerabilities
WebLogic CVE-2021-2397 Vulnerability (CVE-2021-2397)
MySQL CVE-2017-3645 Vulnerability (CVE-2017-3645)
Ruby on Rails Improper Input Validation Vulnerability (CVE-2011-3187)
Internet Information Services Other Vulnerability (CVE-2002-0071)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-0123)