PT-2017-3952 · Openssl · Openssl

Tyler Nighswander

·

Publicado

2017-01-26

·

Atualizado

2017-07-28

·

CVE-2016-7053

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions OpenSSL versions 1.1.0 through 1.1.0c
Description The issue is related to a NULL pointer dereference in the parsing of CMS structures in the OpenSSL library. This can be exploited by a remote attacker to cause a denial of service. The problem arises from the handling of the ASN.1 CHOICE type, which can result in a NULL value being passed to the structure callback when attempting to free certain invalid encodings.
Recommendations For OpenSSL versions 1.1.0 through 1.1.0c, update to version 1.1.0c or later to resolve the issue. As a temporary workaround, consider restricting the use of the CMS parsing functionality until a patch is available. Avoid using the CHOICE structures that do not handle NULL values in the affected API endpoints until the issue is resolved.

Correção

DoS

NULL Pointer Dereference

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2020-02969
CVE-2016-7053

Produtos afetados

Openssl