PT-2016-1332 · Oracle+11 · Mysql Server+11

Adam Langley

·

Publicado

2016-02-22

·

Atualizado

2025-09-29

·

CVE-2016-0705

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions OpenSSL versions 1.0.1 through 1.0.1s OpenSSL versions 1.0.2 through 1.0.2g MySQL Server versions 5.6.29 and earlier MySQL Server versions 5.7.11 and earlier
Description A double free vulnerability in the dsa priv decode function in crypto/dsa/dsa ameth.c in OpenSSL allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a malformed DSA private key. Additionally, a side-channel attack was found which makes use of cache-bank conflicts on the Intel Sandy-Bridge microarchitecture which could lead to the recovery of RSA keys. A vulnerability in the MySQL Server component of Oracle MySQL allows high privileged attackers with network access via multiple protocols to compromise MySQL Server, resulting in unauthorized ability to cause a hang or frequently repeatable crash of MySQL Server.
Recommendations For OpenSSL versions 1.0.1 through 1.0.1s, update to version 1.0.1s or later to resolve the issue. For OpenSSL versions 1.0.2 through 1.0.2g, update to version 1.0.2g or later to resolve the issue. For MySQL Server versions 5.6.29 and earlier, update to version 5.6.30 or later to resolve the issue. For MySQL Server versions 5.7.11 and earlier, update to version 5.7.12 or later to resolve the issue. As a temporary workaround, consider restricting access to the dsa priv decode function in OpenSSL until a patch is available. Avoid using the dsa priv decode function in OpenSSL until the issue is resolved.

Exploit

Correção

Double Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2016-1184
BDU:2016-00631
CESA-2016_0301
CVE-2016-0705
DSA-3500-1
MGASA-2016-0093
OPENSUSE-SU-2016_0627-1
OPENSUSE-SU-2016_0628-1
OPENSUSE-SU-2016_1332-1
OPENSUSE-SU-2016_1566-1
OPENSUSE-SU-2024:10200-1
OPENSUSE-SU-2024:10271-1
OPENSUSE-SU-2024:10529-1
OPENSUSE-SU-2024:11127-1
RHSA-2016:0301
RHSA-2016:0379
RHSA-2016_0301
RHSA-2018:2568
RHSA-2018:2575
RHSA-2018:2713
RHSA-2018_2568
RHSA-2018_2575
SUSE-FU-2022:0445-1
SUSE-SU-2016:0617-1
SUSE-SU-2016:0620-1
SUSE-SU-2016:0621-1
SUSE-SU-2016:0624-1
SUSE-SU-2016:0748-1
SUSE-SU-2016:0778-1
SUSE-SU-2016:0786-1
SUSE-SU-2016:1057-1
SUSE-SU-2018:2839-1
SUSE-SU-2018:2839-2
SUSE-SU-2018:3082-1
SUSE-SU-2018_2839-1
SUSE-SU-2018_2839-2
SUSE-SU-2018_3082-1
USN-2914-1

Produtos afetados

Alt Linux
Centos
Cisco Asa
Cisco Nexus
Freebsd
Ibm Aix
Junos
Mysql Server
Openssl
Red Hat
Suse
Ubuntu