Description
statem/statem.c in OpenSSL 1.1.0a does not consider memory-block movement after a realloc call, which allows remote attackers to cause a denial of service (use-after-free) or possibly execute arbitrary code via a crafted TLS session.
Remediation
References
Related Vulnerabilities
Django Resource Management Errors Vulnerability (CVE-2011-4137)
Lighttpd Other Vulnerability (CVE-2006-0760)
WordPress Plugin Galleries by Angie Makes Cross-Site Scripting (1.67)
Squid Improper Encoding or Escaping of Output Vulnerability (CVE-2021-28662)
WordPress Plugin Zoho CRM Lead Magnet Unspecified Vulnerability (1.7.2.9)