header-logo
Suggest Exploit
vendor:
OpenSSL
by:
Not mentioned
7.5
CVSS
HIGH
Remote Memory-Corruption
Not mentioned
CWE
Product Name: OpenSSL
Affected Version From: OpenSSL 1.0.0a
Affected Version To: Not mentioned
Patch Exists: YES
Related CWE: Not mentioned
CPE: Not mentioned
Metasploit:
Other Scripts:
Platforms Tested: Not mentioned
Not mentioned

OpenSSL Remote Memory-Corruption Vulnerability

The vulnerability allows remote attackers to execute arbitrary code in the context of the application using the vulnerable OpenSSL library. Failed exploit attempts can lead to a denial-of-service condition.

Mitigation:

Apply the latest security patches provided by OpenSSL. Regularly update OpenSSL to the latest version.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/42306/info

OpenSSL is prone to a remote memory-corruption vulnerability.

Successfully exploiting this issue may allow an attacker to execute arbitrary code in the context of the application using the vulnerable library. Failed exploit attempts will result in a denial-of-service condition.

The issue affects OpenSSL 1.0.0a; other versions may also be affected. 

https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/34427.zip