The state-machine implementation in OpenSSL 1.1.0 before 1.1.0a allocates memory before checking for an excessive length, which might allow…
redhat·CWE-400·Published 2016-09-26