Description
Integer overflow in the EVP_EncryptUpdate function in crypto/evp/evp_enc.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (heap memory corruption) via a large amount of data.
Remediation
References
Related Vulnerabilities
OpenSSL Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-1633)
PrestaShop Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-3796)
WordPress Plugin Calendar Event Multi View Unspecified Vulnerability (1.3.58)
WordPress Plugin Google Maps CP Cross-Site Scripting (1.0.3)