PT-2025-31038 · Openssl · Openssl
Published
2023-06-20
·
Updated
2025-07-28
·
CVE-2023-53159
CVSS v3.1
4.5
Vector | AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:L |
Fix
Buffer Over-read
Weakness Enumeration
Related Identifiers
Affected Products
Openssl
Published
2023-06-20
·
Updated
2025-07-28
·
CVE-2023-53159
4.5
Medium
Base vector | Vector | AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:L |
Name of the Vulnerable Software and Affected Versions:
openssl crate versions prior to 0.10.55
Description:
The openssl crate for Rust contains an issue that allows an out-of-bounds read when an empty string is provided to `X509VerifyParamRef::set host`.
Recommendations:
Upgrade to version 0.10.55 or later.
Fix
Buffer Over-read