PT-2016-3289 · Openssl+9 · Openssl+9
Adam Mariš
·
Published
2016-08-11
·
Updated
2024-06-15
·
CVE-2016-6303
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenSSL versions prior to 1.1.0
Description
The issue is caused by an integer overflow in the MDC2 Update function in crypto/mdc2/mdc2dgst.c, allowing remote attackers to cause a denial of service, which may include an out-of-bounds write and application crash, or possibly have other unspecified impacts via unknown vectors.
Recommendations
For versions prior to 1.1.0, update to version 1.1.0 or later to resolve the issue.
As a temporary workaround, consider restricting access to the MDC2 Update function in crypto/mdc2/mdc2dgst.c until a patch is available.
Fix
DoS
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Fortios
Freebsd
Huawei Vrp
Ibm Aix
Junos
Nessus
Openssl
Suse
Ubuntu