CVE-2023-53159

MEDIUM4.5EPSS 0.24%

`openssl` `X509VerifyParamRef::set_host` buffer over-read

發布日:2023/6/21修改日:2025/10/28
也稱為:GHSA-xcf7-rvmh-g6q4CGA-c8rg-7pvv-2wq2DEBIAN-CVE-2023-53159RUSTSEC-2023-0044

描述

When this function was passed an empty string, `openssl` would attempt to call `strlen` on it, reading arbitrary memory until it reached a NUL byte.

受影響套件(3)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM4.5CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:L

參考連結(7)