PT-2016-3289 · Openssl+9 · Openssl+9

Adam Mariš

·

Publicado

2016-08-11

·

Atualizado

2024-06-15

·

CVE-2016-6303

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenSSL versions prior to 1.1.0
Description The issue is caused by an integer overflow in the MDC2 Update function in crypto/mdc2/mdc2dgst.c, allowing remote attackers to cause a denial of service, which may include an out-of-bounds write and application crash, or possibly have other unspecified impacts via unknown vectors.
Recommendations For versions prior to 1.1.0, update to version 1.1.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the MDC2 Update function in crypto/mdc2/mdc2dgst.c until a patch is available.

Correção

DoS

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2016-2005
ALT-PU-2016-2068
BDU:2019-01912
CVE-2016-6303
DLA-637-1
DSA-3673-1
MGASA-2016-0338
MGASA-2016-0408
OPENSUSE-SU-2016_2391-1
OPENSUSE-SU-2016_2407-1
OPENSUSE-SU-2016_2537-1
OPENSUSE-SU-2018_0458-1
OPENSUSE-SU-2024:10271-1
OPENSUSE-SU-2024:11127-1
SUSE-FU-2022:0445-1
SUSE-SU-2016:2387-1
SUSE-SU-2016:2394-1
SUSE-SU-2016:2458-1
SUSE-SU-2016:2468-1
SUSE-SU-2016:2469-1
SUSE-SU-2016:2545-1
SUSE-SU-2017:2699-1
SUSE-SU-2017:2700-1
USN-3087-1
USN-3087-2

Produtos afetados

Alt Linux
Fortios
Freebsd
Huawei Vrp
Ibm Aix
Junos
Nessus
Openssl
Suse
Ubuntu