|
OpenSSL contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when the SSL 3.0 implementation fails to properly initialize data structures used for block cipher padding. When decrypting padding data sent by an SSL peer, a remote attacker can gain access to potentially sensitive information.
|