PT-2026-47841 · Openssl · Openssl
CVSS v3.1
6.2
Medium
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
OpenSSL (affected versions not specified)
Description
An out-of-bounds read occurs when an application calls the
X509 VERIFY PARAM set1 email function to validate a crafted email address, such as during S/MIME message validation. This issue stems from an internal helper function called by X509 VERIFY PARAM set1 email() and X509 VERIFY PARAM add email() that uses an incorrect length when validating the local part of an email address. Consequently, the 64-octet limit for the local part may not be enforced, potentially leading to a crash and Denial of Service. The flaw is reachable via S-MIME validation using a crafted From: address in an email message.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openssl