OpenSSL OCSP Extension Unbounded Memory Denial of Service (CVE-2016-6304)

A denial-of-service vulnerability exists in OpenSSL. A remote, unauthenticated attacker can send an excessively large OCSP Status Request extension and create a denial of service condition.

Leave a Reply