PT-2016-2765 · Openssl+12 · Openssl+13

Shi Lei

·

Published

2016-09-16

·

Updated

2024-06-15

·

CVE-2016-2182

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenSSL versions prior to 1.1.0
Description The issue is related to the BN bn2dec function in the crypto/bn/bn print.c file of the OpenSSL library, which does not properly validate division results. This allows remote attackers to cause a denial of service, such as an out-of-bounds write and application crash, or possibly have other unspecified impacts via unknown vectors.
Recommendations For versions prior to 1.1.0, update to version 1.1.0 or later to resolve the issue. As a temporary workaround, consider restricting the use of the BN bn2dec function until a patch is available.

Fix

DoS

Out of bounds Read

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-2005
BDU:2016-02167
CESA-2016_1940
CVE-2016-2182
DLA-637-1
DSA-3673-1
DSA-3673-2
MGASA-2016-0338
MGASA-2016-0408
OPENSUSE-SU-2016_2391-1
OPENSUSE-SU-2016_2407-1
OPENSUSE-SU-2016_2537-1
OPENSUSE-SU-2018_0458-1
OPENSUSE-SU-2024:10271-1
OPENSUSE-SU-2024:11127-1
RHSA-2016:1940
RHSA-2016_1940
RHSA-2018:2185
RHSA-2018:2186
SUSE-FU-2022:0445-1
SUSE-SU-2016:2387-1
SUSE-SU-2016:2394-1
SUSE-SU-2016:2458-1
SUSE-SU-2016:2468-1
SUSE-SU-2016:2469-1
SUSE-SU-2016:2545-1
SUSE-SU-2017:2699-1
SUSE-SU-2017:2700-1
USN-3087-1
USN-3087-2

Affected Products

Alt Linux
Centos
Cisco Asa
Cisco Nexus
Fortios
Freebsd
Huawei Vrp
Ibm Aix
Junos
Nessus
Openssl
Red Hat
Suse
Ubuntu