PT-2016-1332 · Oracle+11 · Mysql Server+11

Adam Langley

·

Published

2016-02-22

·

Updated

2025-09-29

·

CVE-2016-0705

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions OpenSSL versions 1.0.1 through 1.0.1s OpenSSL versions 1.0.2 through 1.0.2g MySQL Server versions 5.6.29 and earlier MySQL Server versions 5.7.11 and earlier
Description A double free vulnerability in the dsa priv decode function in crypto/dsa/dsa ameth.c in OpenSSL allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a malformed DSA private key. Additionally, a side-channel attack was found which makes use of cache-bank conflicts on the Intel Sandy-Bridge microarchitecture which could lead to the recovery of RSA keys. A vulnerability in the MySQL Server component of Oracle MySQL allows high privileged attackers with network access via multiple protocols to compromise MySQL Server, resulting in unauthorized ability to cause a hang or frequently repeatable crash of MySQL Server.
Recommendations For OpenSSL versions 1.0.1 through 1.0.1s, update to version 1.0.1s or later to resolve the issue. For OpenSSL versions 1.0.2 through 1.0.2g, update to version 1.0.2g or later to resolve the issue. For MySQL Server versions 5.6.29 and earlier, update to version 5.6.30 or later to resolve the issue. For MySQL Server versions 5.7.11 and earlier, update to version 5.7.12 or later to resolve the issue. As a temporary workaround, consider restricting access to the dsa priv decode function in OpenSSL until a patch is available. Avoid using the dsa priv decode function in OpenSSL until the issue is resolved.

Exploit

Fix

Double Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-1184
BDU:2016-00631
CESA-2016_0301
CVE-2016-0705
DSA-3500-1
MGASA-2016-0093
OPENSUSE-SU-2016_0627-1
OPENSUSE-SU-2016_0628-1
OPENSUSE-SU-2016_1332-1
OPENSUSE-SU-2016_1566-1
OPENSUSE-SU-2024:10200-1
OPENSUSE-SU-2024:10271-1
OPENSUSE-SU-2024:10529-1
OPENSUSE-SU-2024:11127-1
RHSA-2016:0301
RHSA-2016:0379
RHSA-2016_0301
RHSA-2018:2568
RHSA-2018:2575
RHSA-2018:2713
RHSA-2018_2568
RHSA-2018_2575
SUSE-FU-2022:0445-1
SUSE-SU-2016:0617-1
SUSE-SU-2016:0620-1
SUSE-SU-2016:0621-1
SUSE-SU-2016:0624-1
SUSE-SU-2016:0748-1
SUSE-SU-2016:0778-1
SUSE-SU-2016:0786-1
SUSE-SU-2016:1057-1
SUSE-SU-2018:2839-1
SUSE-SU-2018:2839-2
SUSE-SU-2018:3082-1
SUSE-SU-2018_2839-1
SUSE-SU-2018_2839-2
SUSE-SU-2018_3082-1
USN-2914-1

Affected Products

Alt Linux
Centos
Cisco Asa
Cisco Nexus
Freebsd
Ibm Aix
Junos
Mysql Server
Openssl
Red Hat
Suse
Ubuntu