PT-2024-21765 · Openssl · Openssl

Published

2024-04-05

·

Updated

2025-06-17

·

CVE-2024-27232

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenSSL (affected versions not specified)
Description The issue is related to a possible out-of-bounds (OOB) read in the asn1 ec pkey parse function of asn1 common.c due to a missing null check. This could lead to local information disclosure without requiring additional execution privileges. User interaction is not needed for exploitation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

NULL Pointer Dereference

Insecure Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2024-27232

Affected Products

Openssl