PT-2017-3952 · Openssl · Openssl

Tyler Nighswander

·

Published

2017-01-26

·

Updated

2017-07-28

·

CVE-2016-7053

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions OpenSSL versions 1.1.0 through 1.1.0c
Description The issue is related to a NULL pointer dereference in the parsing of CMS structures in the OpenSSL library. This can be exploited by a remote attacker to cause a denial of service. The problem arises from the handling of the ASN.1 CHOICE type, which can result in a NULL value being passed to the structure callback when attempting to free certain invalid encodings.
Recommendations For OpenSSL versions 1.1.0 through 1.1.0c, update to version 1.1.0c or later to resolve the issue. As a temporary workaround, consider restricting the use of the CMS parsing functionality until a patch is available. Avoid using the CHOICE structures that do not handle NULL values in the affected API endpoints until the issue is resolved.

Fix

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-02969
CVE-2016-7053

Affected Products

Openssl