A double free or use after free could occur after SSL_clear in OpenBSD 7.2 before errata 026 and 7.3 before errata 004, and in LibreSSL before 3.6.3 and 3.7.x before 3.7.3. NOTE: OpenSSL is not affected.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 08:08
Type | Values Removed | Values Added |
---|---|---|
References | () https://ftp.openbsd.org/pub/OpenBSD/LibreSSL/libressl-3.6.3-relnotes.txt - Release Notes | |
References | () https://ftp.openbsd.org/pub/OpenBSD/LibreSSL/libressl-3.7.3-relnotes.txt - Release Notes | |
References | () https://ftp.openbsd.org/pub/OpenBSD/patches/7.2/common/026_ssl.patch.sig - Patch | |
References | () https://ftp.openbsd.org/pub/OpenBSD/patches/7.3/common/004_ssl.patch.sig - Patch | |
References | () https://github.com/libressl/openbsd/commit/e42d8f4b21a8a498e2eabbffe4c7b7d4ef7cec54 - |
Information
Published : 2023-06-16 20:15
Updated : 2024-11-21 08:08
NVD link : CVE-2023-35784
Mitre link : CVE-2023-35784
CVE.ORG link : CVE-2023-35784
JSON object : View
Products Affected
openbsd
- libressl
- openbsd