In OpenSSL 1.1.0 before 1.1.0c, TLS connections using *-CHACHA20-POLY1305 ciphersuites are susceptible to a DoS attack by corrupting larger payloads. This can result in an OpenSSL crash. This issue is not considered to be exploitable beyond a DoS.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: openssl
Published:
Updated: 2024-09-17T00:30:27.920Z
Reserved: 2016-08-23T00:00:00
Link: CVE-2016-7054
No data.
Status : Deferred
Published: 2017-05-04T19:29:00.257
Modified: 2025-04-20T01:37:25.860
Link: CVE-2016-7054
OpenCVE Enrichment
No data.