PT-2016-7196 · Node.Js+7 · Node.Js+7

Bruce Stephens

+1

·

Publicado

2016-09-26

·

Atualizado

2024-06-15

·

CVE-2016-7052

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenSSL version 1.0.2i nodejs (affected versions not specified) openssl (affected versions not specified)
Description The issue allows remote attackers to cause a denial of service by triggering a CRL operation, resulting in a NULL pointer dereference and application crash.
Recommendations For OpenSSL version 1.0.2i, update to a version that contains a fix for this issue. For nodejs, at the moment, there is no information about a newer version that contains a fix for this issue. For openssl, at the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Correção

DoS

NULL Pointer Dereference

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2016-2068
CVE-2016-7052
FREEBSD-SA-16_27
MGASA-2016-0408
OPENSUSE-SU-2016_2496-1
OPENSUSE-SU-2018_0458-1
OPENSUSE-SU-2024:10247-1
OPENSUSE-SU-2024:10271-1
OPENSUSE-SU-2024:11127-1
SUSE-FU-2022:0445-1
SUSE-SU-2016:2470-1
SUSE-SU-2016:2470-2
SUSE-SU-2019:14246-1
SUSE-SU-2019_14246-1

Produtos afetados

Alt Linux
Freebsd
Huawei Vrp
Ibm Aix
Nessus
Openssl
Suse
Node.Js