PT-2016-3419 · Openssl+12 · Openssl+16

Guido Vranken

·

Publicado

2016-06-19

·

Atualizado

2025-09-29

·

CVE-2016-2177

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions OpenSSL versions 1.0.0 through 1.0.2h OpenSSL (affected versions not specified)
Description The issue is caused by an integer overflow, which might allow remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging unexpected malloc behavior. This is related to incorrect pointer arithmetic for heap-buffer boundary checks in files such as s3 srvr.c, ssl sess.c, and t1 lib.c. The vulnerability could also be exploited to cause the application to crash by attempting to use CRLs due to a missing CRL sanity check.
Recommendations For OpenSSL versions 1.0.0 through 1.0.2h, update to a version later than 1.0.2h to resolve the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability for other affected versions.

Exploit

Correção

DoS

Integer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2016-2005
BDU:2022-02559
CESA-2016_1940
CVE-2016-2177
DLA-637-1
DSA-3673-1
FREEBSD-SA-16_26
MGASA-2016-0338
MGASA-2016-0408
OPENSUSE-SU-2016_2391-1
OPENSUSE-SU-2016_2407-1
OPENSUSE-SU-2016_2537-1
OPENSUSE-SU-2018_0458-1
OPENSUSE-SU-2024:10271-1
OPENSUSE-SU-2024:11127-1
RHSA-2016:1940
RHSA-2016_1940
RHSA-2017:0193
RHSA-2017:0194
RHSA-2017:1658
SUSE-FU-2022:0445-1
SUSE-SU-2016:2387-1
SUSE-SU-2016:2394-1
SUSE-SU-2016:2458-1
SUSE-SU-2016:2468-1
SUSE-SU-2016:2469-1
SUSE-SU-2016:2545-1
SUSE-SU-2016_2387-1
SUSE-SU-2016_2394-1
SUSE-SU-2016_2458-1
SUSE-SU-2016_2468-1
SUSE-SU-2016_2469-1
SUSE-SU-2016_2545-1
SUSE-SU-2017:2699-1
SUSE-SU-2017:2700-1
USN-3087-1
USN-3087-2
USN-3181-1

Produtos afetados

Alt Linux
Centos
Cisco Asa
Cisco Ios Xe
Cisco Ios Xr
Cisco Nexus
Cisco Wls
Fortios
Freebsd
Huawei Vrp
Ibm Aix
Junos
Nessus
Openssl
Red Hat
Suse
Ubuntu