ID:8758 - Exploit for Buffer overflow in OpenSSL - CVE-2022-3786

 
Main Vulnerability Database Exploits ID:8758 - Exploit for Buffer overflow in OpenSSL - CVE-2022-3786

ID:8758 - Exploit for Buffer overflow in OpenSSL - CVE-2022-3786

Published: January 22, 2023


Vulnerability identifier: #VU68896
Vulnerability risk: Medium
CVE-ID: CVE-2022-3786
CWE-ID: CWE-119
Exploitation vector: Remote access
Vulnerable software:
OpenSSL

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error when processing the email address field length inside a X.509 certificate. A remote attacker can supply a specially crafted certificate to the application, trigger a buffer overflow and crash the application.



Remediation

Install updates from vendor's website.