| Details | | | --- | --- | | Package | `openssl` | | Version | `0.10.44` | | URL | https://github.com/sfackler/rust-openssl/issues/1965 | | Patched Versions | >=0.10.55 | | Aliases | [GHSA-xcf7-rvmh-g6q4](https://github.com/advisories/GHSA-xcf7-rvmh-g6q4) | When this function was passed an empty string, `openssl` would attempt to call `strlen` on it, reading arbitrary memory until it reached a NUL byte.