#VU56064 Out-of-bounds read in OpenSSL - CVE-2021-3712
Published: August 24, 2021 / Updated: October 2, 2024
OpenSSL
OpenSSL Software Foundation
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition when processing ASN.1 strings related to a confusion with NULL termination of strings in array. A remote attacker can pass specially crafted data to the application to trigger an out-of-bounds read error and read contents of memory on the system or perform a denial of service (DoS) attack.