It was discovered that pyOpenSSL incorrectly handled memory when performing operations on a PKCS #12 store. A remote attacker could possibly use this issue to cause pyOpenSSL to consume resources, resulting in a denial of service.
This attack appear to be exploitable via Depends upon calling application, however it could be as simple as initiating a TLS connection that would cause the calling application to reload certificates from a PKCS #12 store. This vulnerability appears to have been fixed in 17.5.0.
{ "nvd_published_at": "2018-10-08T15:29:00Z", "cwe_ids": [ "CWE-401", "CWE-404" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2020-06-16T20:52:58Z" }