Severity
Medium
Analysis Summary
CVE-2024-6119
OpenSSL is vulnerable to a denial of service, caused by an error when performing certificate name checks (e.g., TLS clients checking server certificates). By sending a specially crafted request, a remote attacker could exploit this vulnerability to read an invalid memory address resulting in abnormal termination of the application process.
Impact
- Denial of Service
Indicators of Compromise
CVE
- CVE-2024-6119
Affected Vendors
OpenSSL
Affected Products
- OpenSSL - 3.3.0
- OpenSSL - 3.2.0
- OpenSSL - 3.1.0
- OpenSSL - 3.0.0
Remediation
Refer to OpenSSL Security Advisory for patch, upgrade or suggested workaround information.