OSV-2024-430

See a problem?
Import Source
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/boringssl/OSV-2024-430.yaml
JSON Data
https://api.osv.dev/v1/vulns/OSV-2024-430
Withdrawn
2024-05-08T03:26:30Z
Published
2024-05-05T00:14:35.047133Z
Modified
2024-05-08T03:26:30Z
Summary
Use-of-uninitialized-value in ssl_str_to_group_ids
Details

OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=68473

Crash type: Use-of-uninitialized-value
Crash state:
ssl_str_to_group_ids
SSL_CTX_set1_groups_list
std::__1::__function::__func<LLVMFuzzerTestOneInput::$_34, std::__1::allocator<L
References

Affected packages

OSS-Fuzz / boringssl

Package

Name
boringssl
Purl
pkg:generic/boringssl

Affected ranges

Type
GIT
Repo
https://boringssl.googlesource.com/boringssl
Events

Ecosystem specific

{
    "severity": "MEDIUM"
}

Database specific

fixed_range
"d2e3212de29bac1ceed33ca8ab8bbff3f41a2459:3e89a7e8db8139db356b892ca9993172346c80cf"
source
"https://github.com/google/oss-fuzz-vulns/blob/main/vulns/boringssl/OSV-2024-430.yaml"
introduced_range
"d69e8b46184b6fd844a4a92b4a6f4347d08ee439:2db0eb3f96a5756298dcd7f9319e56a98585bd10"