« List of all CVEs

CVE-2017-3733

Encrypt-Then-Mac renegotiation crash

Published: 5/4/2017 Last updated: 9/16/2024 Reserved: 12/16/2016

During a renegotiation handshake if the Encrypt-Then-Mac extension is negotiated where it was not in the original handshake (or vice-versa) then this can cause OpenSSL 1.1.0 before 1.1.0e to crash (dependent on ciphersuite). Both clients and servers are affected.

CNA assigner: openssl (3a12439a-ef3a-4c79-92e6-6081a721f1e5) Requested by: n/a

Opam packages affected (6)

conf-libcurl conf-libssl conf-mingw-w64-openssl-i686 conf-mingw-w64-openssl-x86_64 conf-openssl conf-srt-openssl

Products affected (1)

Product Vendor Version
OpenSSL OpenSSL < 6.0.6003.23016

References (16)

Credits (1)