CVE-2016-6306

MEDIUM

OpenSSL <1.0.1u, <1.0.2i - DoS

Title source: llm
STIX 2.1

Description

The certificate parser in OpenSSL before 1.0.1u and 1.0.2 before 1.0.2i might allow remote attackers to cause a denial of service (out-of-bounds read) via crafted certificate operations, related to s3_clnt.c and s3_srvr.c.

References (56)

Core 56
Core References
Third Party Advisory vendor-advisory
https://access.redhat.com/errata/RHSA-2018:2185
Third Party Advisory vendor-advisory
https://access.redhat.com/errata/RHSA-2018:2186
Third Party Advisory, VDB Entry vdb-entry
http://www.securityfocus.com/bid/93153
Third Party Advisory vendor-advisory
http://rhn.redhat.com/errata/RHSA-2016-1940.html
Third Party Advisory vendor-advisory
https://security.gentoo.org/glsa/201612-16
Third Party Advisory, VDB Entry vdb-entry
http://www.securitytracker.com/id/1036885
Mailing List, Third Party Advisory vendor-advisory
http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00013.html
Third Party Advisory vendor-advisory
https://access.redhat.com/errata/RHSA-2018:2187
Third Party Advisory vendor-advisory
http://www.ubuntu.com/usn/USN-3087-1
Mailing List, Third Party Advisory vendor-advisory
http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00012.html
Third Party Advisory vendor-advisory
http://www.ubuntu.com/usn/USN-3087-2
Mailing List, Third Party Advisory vendor-advisory
http://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html
Mailing List, Third Party Advisory vendor-advisory
http://lists.opensuse.org/opensuse-security-announce/2016-09/msg00031.html
Mailing List, Third Party Advisory mailing-list
http://seclists.org/fulldisclosure/2017/Jul/31
Third Party Advisory vendor-advisory
http://www.debian.org/security/2016/dsa-3673
Mailing List, Third Party Advisory vendor-advisory
http://lists.opensuse.org/opensuse-security-announce/2018-02/msg00032.html
Mailing List, Third Party Advisory vendor-advisory
http://lists.opensuse.org/opensuse-security-announce/2016-09/msg00022.html
Mailing List, Third Party Advisory vendor-advisory
http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00021.html
Mailing List, Third Party Advisory vendor-advisory
http://lists.opensuse.org/opensuse-security-announce/2016-09/msg00024.html

Scores

CVSS v3 5.9
EPSS 0.0813
EPSS Percentile 92.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-125
Status published
Products (40)
canonical/ubuntu_linux 12.04
canonical/ubuntu_linux 14.04
canonical/ubuntu_linux 16.04
debian/debian_linux 8.0
hp/icewall_federation_agent 3.0
hp/icewall_mcrp 3.0
hp/icewall_sso 10.0 (2 CPE variants)
hp/icewall_sso_agent_option 10.0
nodejs/node.js 0.10.0 - 0.10.47
nodejs/node.js 4.2.0 - 4.6.0
... and 30 more
Published Sep 26, 2016
Tracked Since Feb 18, 2026