CVE-2023-53159

MEDIUM4.5EPSS 0.24%

`openssl` `X509VerifyParamRef::set_host` buffer over-read

Published: 6/21/2023Modified: 4/28/2026
Also known as:GHSA-xcf7-rvmh-g6q4CGA-c8rg-7pvv-2wq2DEBIAN-CVE-2023-53159RUSTSEC-2023-0044

Description

The openssl crate before 0.10.55 for Rust allows an out-of-bounds read via an empty string to X509VerifyParamRef::set_host.

Affected packages (3)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM4.5CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:L

References (7)