OpenSSL tls_get_message_body Function init_msg Structure Use After Free (CVE-2016-6309)

A use-after-free vulnerability has been reported in the tls_get_message_body function of OpenSSL. A remote, unauthenticated attacker could exploit this vulnerability by sending a crafted message to the vulnerable server. Successful exploitation allows the attacker to execute arbitrary code on the system.

Leave a Reply