#VU89624 Resource management error in OpenSSL - CVE-2024-4603
Published: May 17, 2024 / Updated: February 5, 2025
OpenSSL
OpenSSL Software Foundation
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper management of internal resources within the application when checking DSA keys and parameters. A remote attacker can pass specially crafted data to the application and perform a denial of service (DoS) attack.
Remediation
External links
- https://www.openssl.org/news/secadv/20240516.txt
- https://github.com/openssl/openssl/commit/3559e868e58005d15c6013a0c1fd832e51c73397
- https://github.com/openssl/openssl/commit/9c39b3858091c152f52513c066ff2c5a47969f0d
- https://github.com/openssl/openssl/commit/da343d0605c826ef197aceedc67e8e04f065f740
- https://github.com/openssl/openssl/commit/53ea06486d296b890d565fb971b2764fcd826e7e