5.5
CVSSv3

CVE-2021-41581

Published: 24/09/2021 Updated: 29/09/2021
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

x509_constraints_parse_mailbox in lib/libcrypto/x509/x509_constraints.c in LibreSSL up to and including 3.4.0 has a stack-based buffer over-read. When the input exceeds DOMAIN_PART_MAX_LEN, the buffer lacks '\0' termination.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openbsd libressl

Vendor Advisories

x509_constraints_parse_mailbox in lib/libcrypto/x509/x509_constraintsc in LibreSSL through 340 has a stack-based buffer over-read When the input exceeds DOMAIN_PART_MAX_LEN, the buffer lacks '\0' termination ...