PT-2016-3289 · Openssl+9 · Openssl+9
Adam Mariš
·
Publicado
2016-08-11
·
Atualizado
2024-06-15
·
CVE-2016-6303
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenSSL versions prior to 1.1.0
Description
The issue is caused by an integer overflow in the MDC2 Update function in crypto/mdc2/mdc2dgst.c, allowing remote attackers to cause a denial of service, which may include an out-of-bounds write and application crash, or possibly have other unspecified impacts via unknown vectors.
Recommendations
For versions prior to 1.1.0, update to version 1.1.0 or later to resolve the issue.
As a temporary workaround, consider restricting access to the MDC2 Update function in crypto/mdc2/mdc2dgst.c until a patch is available.
Correção
DoS
Memory Corruption
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Fortios
Freebsd
Huawei Vrp
Ibm Aix
Junos
Nessus
Openssl
Suse
Ubuntu