CVE-2016-7054
HIGHOpenSSL 1.1.0-1.1.0b - Denial of Service via CHACHA20-POLY1305 Cipher Payload Corruption
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2016-7054. PoCs published by Silverfox.
AI-analyzed exploit summary This exploit demonstrates a heap overflow in OpenSSL 1.1.0a and 1.1.0b by negotiating ChaCha20-Poly1305 cipher suites and sending a malformed message with a bad MAC, causing a denial of service (DoS). The PoC uses the tlsfuzzer library to craft a TLS handshake with a tampered payload.
Description
In OpenSSL 1.1.0 before 1.1.0c, TLS connections using *-CHACHA20-POLY1305 ciphersuites are susceptible to a DoS attack by corrupting larger payloads. This can result in an OpenSSL crash. This issue is not considered to be exploitable beyond a DoS.
Exploits (1)
This exploit demonstrates a heap overflow in OpenSSL 1.1.0a and 1.1.0b by negotiating ChaCha20-Poly1305 cipher suites and sending a malformed message with a bad MAC, causing a denial of service (DoS). The PoC uses the tlsfuzzer library to craft a TLS handshake with a tampered payload.
References (5)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H