A AegiFlow
HIGHCVSS 7.5

CVE-2017-3733

CVE-2017-3733 updated by NVD

Modified
2026-09-20
Sources
nvd

Summary

During a renegotiation handshake if the Encrypt-Then-Mac extension is negotiated where it was not in the original handshake (or vice-versa) then this can cause OpenSSL 1.1.0 before 1.1.0e to crash (dependent on ciphersuite). Both clients and servers are affected.

Affected packages

EcosystemPackageAffected versionsFixed versions
OpenSSLopenssl[object Object], [object Object], [object Object], [object Object], [object Object]

References

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.