All vulnerabilities

CVE-2021-23840

Integer overflow in CipherUpdate

Description

Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflowthe output length argument in some cases where the input length is close to themaximum permissable length for an integer on the platform. In such cases thereturn value from the function call will be 1 (indicating success), but theoutput length value will be negative. This could cause applications to behaveincorrectly or crash.

Patch Available

Fix available through Seal Security. 

No upgrade required, protect your application instantly.

Fix without upgrading
Score
Severity
Ecosystem
RPM
Publish Date
May 1, 2021
Modified Date
December 16, 2024
Score Vector
Affected Versions