CVE-2016-7054
04.05.2017, 19:29
In OpenSSL 1.1.0 before 1.1.0c, TLS connections using *-CHACHA20-POLY1305 ciphersuites are susceptible to a DoS attack by corrupting larger payloads. This can result in an OpenSSL crash. This issue is not considered to be exploitable beyond a DoS.Enginsight
Vendor | Product | Version |
---|---|---|
openssl | openssl | 1.1.0 |
openssl | openssl | 1.1.0a:a |
openssl | openssl | 1.1.0b:b |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References