Integer Underflow Vulnerability in OpenSSL

Integer Underflow Vulnerability in OpenSSL

CVE-2012-2333 · MEDIUM Severity

AV:N/AC:M/AU:N/C:P/I:P/A:P

Integer underflow in OpenSSL before 0.9.8x, 1.0.0 before 1.0.0j, and 1.0.1 before 1.0.1c, when TLS 1.1, TLS 1.2, or DTLS is used with CBC encryption, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted TLS packet that is not properly handled during a certain explicit IV calculation.

Learn more about our Web Application Penetration Testing UK.