CVE-2023-5363 | OpenSSL up to 3.0.11/3.1.3 Length keylen/ivlen buffer over-read
A vulnerability was found in OpenSSL up to 3.0.11/3.1.3 and classified as critical. This issue affects the function EVP_EncryptInit_ex2/EVP_DecryptInit_ex2/EVP_CipherInit_ex2 of the component Length Handler. The manipulation of the argument keylen/ivlen leads to buffer over-read.
The identification of this vulnerability is CVE-2023-5363. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.