When this function was passed an empty string, openssl would attempt to call strlen on it, reading arbitrary memory until it reached a NUL byte.
{
"github_reviewed": true,
"github_reviewed_at": "2023-06-21T22:07:52Z",
"cwe_ids": [
"CWE-126"
],
"nvd_published_at": null,
"severity": "MODERATE"
}