PT-2016-1336 · Openssl+3 · Openssl+3

·

CVE-2016-2842

·

Publicado

2016-03-01

·

Atualizado

2025-09-25

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenSSL versions 1.0.1 through 1.0.1s OpenSSL versions 1.0.2 through 1.0.2g
Description The issue is related to the doapr outch function in OpenSSL, which does not verify that a certain memory allocation succeeds. This allows remote attackers to cause a denial of service, such as an out-of-bounds write or excessive memory consumption, by sending a long string, for example, a large amount of ASN.1 data.
Recommendations For OpenSSL versions 1.0.1 through 1.0.1s, update to version 1.0.1s or later. For OpenSSL versions 1.0.2 through 1.0.2g, update to version 1.0.2g or later. As a temporary workaround, consider restricting the input size to prevent excessive memory allocation until a patch is applied.

Exploit

Correção

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2016-00635
CESA-2016_0722
CESA-2016_0996
CVE-2016-2842
DSA-3500-1
RHSA-2016:0722
RHSA-2016:0996
RHSA-2016:2073
RHSA-2016_0722
RHSA-2016_0996

Produtos afetados

Centos
Ibm Aix
Openssl
Red Hat