#VU5839 Improper input validation in OpenSSL - CVE-2017-3733
Published: February 16, 2017
OpenSSL
OpenSSL Software Foundation
Description
The vulnerability allows a remote attacker to cause denial of service.
The vulnerability exists due to improper input validation during a renegotiation handshake, if the Encrypt-Then-Mac extension is negotiated where it was not in the original handshake. A remote attacker can send a specially crafted data to vulnerable application and case denial of service conditions.
Successful exploitation of the vulnerability may result in denial of service (DoS) attack.