PT-2016-2765 · Openssl+12 · Openssl+13
Shi Lei
·
Published
2016-09-16
·
Updated
2024-06-15
·
CVE-2016-2182
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenSSL versions prior to 1.1.0
Description
The issue is related to the BN bn2dec function in the crypto/bn/bn print.c file of the OpenSSL library, which does not properly validate division results. This allows remote attackers to cause a denial of service, such as an out-of-bounds write and application crash, or possibly have other unspecified impacts via unknown vectors.
Recommendations
For versions prior to 1.1.0, update to version 1.1.0 or later to resolve the issue. As a temporary workaround, consider restricting the use of the BN bn2dec function until a patch is available.
Fix
DoS
Out of bounds Read
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Centos
Cisco Asa
Cisco Nexus
Fortios
Freebsd
Huawei Vrp
Ibm Aix
Junos
Nessus
Openssl
Red Hat
Suse
Ubuntu