PT-2016-3289 · Openssl+9 · Openssl+9

Adam Mariš

·

Published

2016-08-11

·

Updated

2024-06-15

·

CVE-2016-6303

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenSSL versions prior to 1.1.0
Description The issue is caused by an integer overflow in the MDC2 Update function in crypto/mdc2/mdc2dgst.c, allowing remote attackers to cause a denial of service, which may include an out-of-bounds write and application crash, or possibly have other unspecified impacts via unknown vectors.
Recommendations For versions prior to 1.1.0, update to version 1.1.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the MDC2 Update function in crypto/mdc2/mdc2dgst.c until a patch is available.

Fix

DoS

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-2005
ALT-PU-2016-2068
BDU:2019-01912
CVE-2016-6303
DLA-637-1
DSA-3673-1
MGASA-2016-0338
MGASA-2016-0408
OPENSUSE-SU-2016_2391-1
OPENSUSE-SU-2016_2407-1
OPENSUSE-SU-2016_2537-1
OPENSUSE-SU-2018_0458-1
OPENSUSE-SU-2024:10271-1
OPENSUSE-SU-2024:11127-1
SUSE-FU-2022:0445-1
SUSE-SU-2016:2387-1
SUSE-SU-2016:2394-1
SUSE-SU-2016:2458-1
SUSE-SU-2016:2468-1
SUSE-SU-2016:2469-1
SUSE-SU-2016:2545-1
SUSE-SU-2017:2699-1
SUSE-SU-2017:2700-1
USN-3087-1
USN-3087-2

Affected Products

Alt Linux
Fortios
Freebsd
Huawei Vrp
Ibm Aix
Junos
Nessus
Openssl
Suse
Ubuntu