Description
The state-machine implementation in OpenSSL 1.1.0 before 1.1.0a allocates memory before checking for an excessive length, which might allow remote attackers to cause a denial of service (memory consumption) via crafted TLS messages, related to statem/statem.c and statem/statem_lib.c.
Remediation
References
Related Vulnerabilities
Oracle HTTP Server CVE-2018-2760 Vulnerability (CVE-2018-2760)
Jboss EAP Deserialization of Untrusted Data Vulnerability (CVE-2019-14893)
PHP Release of Invalid Pointer or Reference Vulnerability (CVE-2022-31625)
WordPress Plugin Import all XML, CSV & TXT into WordPress Server-Side Request Forgery (6.5.2)