PT-2016-1336 · Openssl+3 · Openssl+3
CVSS v3.1
10
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenSSL versions 1.0.1 through 1.0.1s
OpenSSL versions 1.0.2 through 1.0.2g
Description
The issue is related to the
doapr outch function in OpenSSL, which does not verify that a certain memory allocation succeeds. This allows remote attackers to cause a denial of service, such as an out-of-bounds write or excessive memory consumption, by sending a long string, for example, a large amount of ASN.1 data.Recommendations
For OpenSSL versions 1.0.1 through 1.0.1s, update to version 1.0.1s or later.
For OpenSSL versions 1.0.2 through 1.0.2g, update to version 1.0.2g or later.
As a temporary workaround, consider restricting the input size to prevent excessive memory allocation until a patch is applied.
Exploit
Correção
DoS
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Centos
Ibm Aix
Openssl
Red Hat