Problemunvalidated
stack buffer overflow vulnerability in OpenSSL 3.0.0-3.0.6 — when processing X.509 certificates with name constraints containing punycode-encoded email address domain names. Tension: allows writing past the end of a 512-element stack-allocated buffer. Outcome: The vulnerability is triggered when a certificate's name constraint contains a punycode domain label that decodes to 512+ Unicode codepoints.
030d06d4-353a-4716-ae95-97d5e07ee181
stack buffer overflow vulnerability in OpenSSL 3.0.0-3.0.6 — when processing X.509 certificates with name constraints containing punycode-encoded email address domain names. Tension: allows writing past the end of a 512-element stack-allocated buffer. Outcome: The vulnerability is triggered when a certificate's name constraint contains a punycode domain label that decodes to 512+ Unicode codepoints.