CVE-2021-3712 | OpenSSL up to 1.0.2y/1.1.1k ASN.1 out-of-bounds (Nessus ID 211827)
A vulnerability was found in OpenSSL up to 1.0.2y/1.1.1k. It has been declared as problematic. Affected by this vulnerability is the function d2i/X509_get1_email/X509_REQ_get1_email/X509_get1_ocsp of the component ASN.1 Handler. The manipulation leads to out-of-bounds read.
This vulnerability is known as CVE-2021-3712. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.