PT-2016-1335 · Openssl+9 · Openssl+12

Guido Vranken

·

Publicado

2016-03-01

·

Atualizado

2022-12-13

·

CVE-2016-0799

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenSSL versions 1.0.1 through 1.0.1s OpenSSL versions 1.0.2 through 1.0.2g
Description The issue is related to the fmtstr function in crypto/bio/b print.c, which improperly calculates string lengths. This allows remote attackers to cause a denial of service or possibly have other impacts via a long string, such as a large amount of ASN.1 data. A side-channel attack was also found, which could lead to the recovery of RSA keys using cache-bank conflicts on the Intel Sandy-Bridge microarchitecture.
Recommendations For OpenSSL versions 1.0.1 through 1.0.1s, update to version 1.0.1s or later. For OpenSSL versions 1.0.2 through 1.0.2g, update to version 1.0.2g or later. As a temporary workaround, consider restricting the use of the fmtstr function in crypto/bio/b print.c to minimize the risk of exploitation. Avoid using long "%s" format strings in the BIO *printf functions until the issue is resolved.

Exploit

Correção

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2016-1184
BDU:2016-00634
CESA-2016_0722
CESA-2016_0996
CVE-2016-0799
DSA-3500-1
MGASA-2016-0093
OPENSUSE-SU-2016_0627-1
OPENSUSE-SU-2016_0628-1
OPENSUSE-SU-2016_0640-1
OPENSUSE-SU-2016_0720-1
OPENSUSE-SU-2016_1241-1
RHSA-2016:0722
RHSA-2016:0996
RHSA-2016:2073
RHSA-2016_0722
RHSA-2016_0996
SUSE-FU-2022:0445-1
SUSE-SU-2016:0617-1
SUSE-SU-2016:0620-1
SUSE-SU-2016:0621-1
SUSE-SU-2016:0624-1
SUSE-SU-2016:0631-1
SUSE-SU-2016:0641-1
SUSE-SU-2016:0748-1
SUSE-SU-2016:0778-1
SUSE-SU-2016:0786-1
SUSE-SU-2016:1057-1
USN-2914-1

Produtos afetados

Alt Linux
Centos
Cisco Asa
Cisco Ios
Cisco Nexus
Cisco Wls
Freebsd
Ibm Aix
Junos
Openssl
Red Hat
Suse
Ubuntu