PT-2016-3308 · Mysql Server+11 · Mysql Server+12

Guido Vranken

·

Publicado

2016-05-03

·

Atualizado

2024-06-15

·

CVE-2016-2105

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions OpenSSL versions prior to 1.0.1t and 1.0.2h MySQL Server versions 5.6.30 and earlier, 5.7.12 and earlier
Description The issue is related to an integer overflow in the EVP EncodeUpdate function in OpenSSL, which can cause a denial of service or potentially allow remote attackers to execute arbitrary code. This is due to improper bounds checking, allowing an attacker to overflow a buffer by sending a large amount of binary data. The vulnerability can be exploited by an unauthenticated, remote attacker. It affects various products, including MySQL Server, and can result in unauthorized ability to cause a hang or crash of the server.
Recommendations For OpenSSL versions prior to 1.0.1t and 1.0.2h, update to version 1.0.1t or 1.0.2h or later to resolve the issue. For MySQL Server versions 5.6.30 and earlier, 5.7.12 and earlier, update to a version later than 5.6.30 or 5.7.12 to resolve the issue. As a temporary workaround, consider restricting access to the EVP EncodeUpdate function until a patch is available.

Exploit

Correção

DoS

Integer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2016-1438
ALT-PU-2016-1439
ALT-PU-2016-1623
BDU:2020-02960
CESA-2016_0722
CESA-2016_0996
CVE-2016-2105
DLA-456-1
DSA-3566-1
FREEBSD-SA-16_17
MGASA-2016-0169
OPENSUSE-SU-2016_1238-1
OPENSUSE-SU-2016_1240-1
OPENSUSE-SU-2016_1241-1
OPENSUSE-SU-2016_1242-1
OPENSUSE-SU-2016_1243-1
OPENSUSE-SU-2016_1273-1
OPENSUSE-SU-2016_1566-1
OPENSUSE-SU-2016_2769-1
OPENSUSE-SU-2016_2788-1
OPENSUSE-SU-2024:10200-1
OPENSUSE-SU-2024:10271-1
OPENSUSE-SU-2024:10529-1
OPENSUSE-SU-2024:11127-1
RHSA-2016:0722
RHSA-2016:0996
RHSA-2016:1648
RHSA-2016:1649
RHSA-2016:2073
RHSA-2016_0722
RHSA-2016_0996
SUSE-FU-2022:0445-1
SUSE-SU-2016:1206-1
SUSE-SU-2016:1228-1
SUSE-SU-2016:1231-1
SUSE-SU-2016:1233-1
SUSE-SU-2016:1267-1
SUSE-SU-2016:1290-1
SUSE-SU-2016_1231-1
SUSE-SU-2017:2699-1
SUSE-SU-2017:2700-1
USN-2959-1

Produtos afetados

Alt Linux
Centos
Cisco Nexus
Cisco Wls
Freebsd
Huawei Vrp
Ibm Aix
Junos
Mysql Server
Openssl
Red Hat
Suse
Ubuntu