openssl is vulnerable to Denial of Service (DoS)
37
Low Risk
While a DTLS handshake is in progress, OpenSSL buffers a record that claims to belong to the next epoch by retaining the whole read buffer, about 16 kilobytes, instead of the record bytes. A peer can send many small records of that kind, up to the cap of 100 per connection, and force the endpoint to hold far more memory than the bytes on the wire, which can exhaust a DTLS server that accepts many associations. The fix stores only the record bytes.
You are affected if you are using a version that falls within the vulnerable range and your application uses DTLS.
openssl is vulnerable to Denial of Service (DoS) in versions 1.0.2 - 3.0.21, 3.4.0 - 3.4.6, 3.5.0 - 3.5.7, 3.6.0 - 3.6.3 and 4.0.0 - 4.0.1.
Upgrade the openssl library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.