Risk | High |
Patch available | YES |
Number of vulnerabilities | 7 |
CVE-ID | CVE-2016-0799 CVE-2016-2105 CVE-2016-2106 CVE-2016-2107 CVE-2016-2108 CVE-2016-2109 CVE-2016-2842 |
CWE-ID | CWE-119 CWE-20 CWE-284 CWE-120 |
Exploitation vector | Network |
Public exploit | Public exploit code for vulnerability #4 is available. |
Vulnerable software |
Red Hat Enterprise Linux Server from RHUI Operating systems & Components / Operating system Red Hat Enterprise Linux for Power, little endian - Extended Update Support Operating systems & Components / Operating system Red Hat Enterprise Linux EUS Compute Node Operating systems & Components / Operating system Red Hat Enterprise Linux for Power, big endian - Extended Update Support Operating systems & Components / Operating system Red Hat Enterprise Linux for IBM z Systems - Extended Update Support Operating systems & Components / Operating system Red Hat Enterprise Linux Server - Extended Update Support Operating systems & Components / Operating system Red Hat Enterprise Linux Server - TUS Operating systems & Components / Operating system Red Hat Enterprise Linux Server - AUS Operating systems & Components / Operating system Red Hat Enterprise Linux for Power, little endian Operating systems & Components / Operating system Red Hat Enterprise Linux for Power, big endian Operating systems & Components / Operating system Red Hat Enterprise Linux for IBM z Systems Operating systems & Components / Operating system Red Hat Enterprise Linux for Scientific Computing Operating systems & Components / Operating system Red Hat Enterprise Linux Desktop Operating systems & Components / Operating system Red Hat Enterprise Linux Workstation Operating systems & Components / Operating system Red Hat Enterprise Linux Server Operating systems & Components / Operating system openssl (Red Hat package) Operating systems & Components / Operating system package or component |
Vendor | Red Hat Inc. |
Security Bulletin
This security bulletin contains information about 7 vulnerabilities.
EUVDB-ID: #VU82376
Risk: High
CVSSv4.0: 8.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber]
CVE-ID: CVE-2016-0799
CWE-ID:
CWE-119 - Memory corruption
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to fmtstr function in crypto/bio/b_print.c in OpenSSL improperly calculates string lengths. A remote attacker can cause a denial of service (overflow and out-of-bounds read) or possibly have unspecified other impact via a long string.
MitigationInstall updates from vendor's website.
Red Hat Enterprise Linux Server from RHUI: 7.0
Red Hat Enterprise Linux for Power, little endian - Extended Update Support: 7.2 - 7.3
Red Hat Enterprise Linux EUS Compute Node: 7.2 - 7.3
Red Hat Enterprise Linux for Power, big endian - Extended Update Support: 7.2 - 7.3
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support: 7.2 - 7.3
Red Hat Enterprise Linux Server - Extended Update Support: 7.2 - 7.3
Red Hat Enterprise Linux Server - TUS: 7.2 - 7.3
Red Hat Enterprise Linux Server - AUS: 7.2 - 7.3
Red Hat Enterprise Linux for Power, little endian: 7
Red Hat Enterprise Linux for Power, big endian: 7
Red Hat Enterprise Linux for IBM z Systems: 7
Red Hat Enterprise Linux for Scientific Computing: 7
Red Hat Enterprise Linux Desktop: 7
Red Hat Enterprise Linux Workstation: 7
Red Hat Enterprise Linux Server: 7
openssl (Red Hat package): before 1.0.1e-51.el7_2.5
CPE2.3https://access.redhat.com/errata/RHSA-2016:0722
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU640
Risk: Low
CVSSv4.0: 2.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2016-2105
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a remote user to cause heap overflow on the target system.
The weakness is caused by insufficient input validation. By sending a great deal of input data attackers are able to cause overflow of the EVP_EncodeUpdate() function used for binary data encoding.
Successful exploitation of the vulnerability may result in heap overflow on the vulnerable system.
Install updates from vendor's website.
Red Hat Enterprise Linux Server from RHUI: 7.0
Red Hat Enterprise Linux for Power, little endian - Extended Update Support: 7.2 - 7.3
Red Hat Enterprise Linux EUS Compute Node: 7.2 - 7.3
Red Hat Enterprise Linux for Power, big endian - Extended Update Support: 7.2 - 7.3
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support: 7.2 - 7.3
Red Hat Enterprise Linux Server - Extended Update Support: 7.2 - 7.3
Red Hat Enterprise Linux Server - TUS: 7.2 - 7.3
Red Hat Enterprise Linux Server - AUS: 7.2 - 7.3
Red Hat Enterprise Linux for Power, little endian: 7
Red Hat Enterprise Linux for Power, big endian: 7
Red Hat Enterprise Linux for IBM z Systems: 7
Red Hat Enterprise Linux for Scientific Computing: 7
Red Hat Enterprise Linux Desktop: 7
Red Hat Enterprise Linux Workstation: 7
Red Hat Enterprise Linux Server: 7
openssl (Red Hat package): before 1.0.1e-51.el7_2.5
CPE2.3https://access.redhat.com/errata/RHSA-2016:0722
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU33809
Risk: Medium
CVSSv4.0: 6.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2016-2106
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
Integer overflow in the EVP_EncryptUpdate function in crypto/evp/evp_enc.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (heap memory corruption) via a large amount of data.
MitigationInstall updates from vendor's website.
Red Hat Enterprise Linux Server from RHUI: 7.0
Red Hat Enterprise Linux for Power, little endian - Extended Update Support: 7.2 - 7.3
Red Hat Enterprise Linux EUS Compute Node: 7.2 - 7.3
Red Hat Enterprise Linux for Power, big endian - Extended Update Support: 7.2 - 7.3
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support: 7.2 - 7.3
Red Hat Enterprise Linux Server - Extended Update Support: 7.2 - 7.3
Red Hat Enterprise Linux Server - TUS: 7.2 - 7.3
Red Hat Enterprise Linux Server - AUS: 7.2 - 7.3
Red Hat Enterprise Linux for Power, little endian: 7
Red Hat Enterprise Linux for Power, big endian: 7
Red Hat Enterprise Linux for IBM z Systems: 7
Red Hat Enterprise Linux for Scientific Computing: 7
Red Hat Enterprise Linux Desktop: 7
Red Hat Enterprise Linux Workstation: 7
Red Hat Enterprise Linux Server: 7
openssl (Red Hat package): before 1.0.1e-51.el7_2.5
CPE2.3https://access.redhat.com/errata/RHSA-2016:0722
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU639
Risk: High
CVSSv4.0: 7.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/U:Amber]
CVE-ID: CVE-2016-2107
CWE-ID:
CWE-284 - Improper Access Control
Exploit availability: Yes
DescriptionThe vulnerability allows a remote user to decrypt traffic on the target system.
The weakness is due to access control error.If the connection uses an AES CBC cipher and the server support AES-NI attackers can perform padding oracle attack.
Successful exploitation of the vulnerability leads to traffic decryption on the vulnerable system.
Install updates from vendor's website.
Red Hat Enterprise Linux Server from RHUI: 7.0
Red Hat Enterprise Linux for Power, little endian - Extended Update Support: 7.2 - 7.3
Red Hat Enterprise Linux EUS Compute Node: 7.2 - 7.3
Red Hat Enterprise Linux for Power, big endian - Extended Update Support: 7.2 - 7.3
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support: 7.2 - 7.3
Red Hat Enterprise Linux Server - Extended Update Support: 7.2 - 7.3
Red Hat Enterprise Linux Server - TUS: 7.2 - 7.3
Red Hat Enterprise Linux Server - AUS: 7.2 - 7.3
Red Hat Enterprise Linux for Power, little endian: 7
Red Hat Enterprise Linux for Power, big endian: 7
Red Hat Enterprise Linux for IBM z Systems: 7
Red Hat Enterprise Linux for Scientific Computing: 7
Red Hat Enterprise Linux Desktop: 7
Red Hat Enterprise Linux Workstation: 7
Red Hat Enterprise Linux Server: 7
openssl (Red Hat package): before 1.0.1e-51.el7_2.5
CPE2.3https://access.redhat.com/errata/RHSA-2016:0722
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability. However, proof of concept for this vulnerability is available.
EUVDB-ID: #VU638
Risk: High
CVSSv4.0: 8.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber]
CVE-ID: CVE-2016-2108
CWE-ID:
CWE-120 - Buffer overflow
Exploit availability: No
DescriptionThe vulnerability allows a remote user to cause memory corruption on the target system.
The weakness exists due to buffer underflow with an out-of-bounds write in i2c_ASN1_INTEGER. As ASN.1 parser (specifically, d2i_ASN1_TYPE) can misinterpret a large universal tag as a negative zero value, attacker may easily corrupt memory.
Successful exploitation of the vulnerability will allow a malicious user to trigger memory corruption on the vulnerable system.
Install updates from vendor's website.
Red Hat Enterprise Linux Server from RHUI: 7.0
Red Hat Enterprise Linux for Power, little endian - Extended Update Support: 7.2 - 7.3
Red Hat Enterprise Linux EUS Compute Node: 7.2 - 7.3
Red Hat Enterprise Linux for Power, big endian - Extended Update Support: 7.2 - 7.3
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support: 7.2 - 7.3
Red Hat Enterprise Linux Server - Extended Update Support: 7.2 - 7.3
Red Hat Enterprise Linux Server - TUS: 7.2 - 7.3
Red Hat Enterprise Linux Server - AUS: 7.2 - 7.3
Red Hat Enterprise Linux for Power, little endian: 7
Red Hat Enterprise Linux for Power, big endian: 7
Red Hat Enterprise Linux for IBM z Systems: 7
Red Hat Enterprise Linux for Scientific Computing: 7
Red Hat Enterprise Linux Desktop: 7
Red Hat Enterprise Linux Workstation: 7
Red Hat Enterprise Linux Server: 7
openssl (Red Hat package): before 1.0.1e-51.el7_2.5
CPE2.3https://access.redhat.com/errata/RHSA-2016:0722
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU641
Risk: Low
CVSSv4.0: 2.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2016-2109
CWE-ID:
CWE-119 - Memory corruption
Exploit availability: No
DescriptionThe vulnerability allows a remote user to cause excessive memory allocation on the target system.
The weakness exists during reading ASN.1 data by d2i_CMS_bio() function. A short invalid encoding leads to distribution of large amounts of memory for excessive resources or exhausting memory.
Successful exploitation of the vulnerability may result in excessive memory allocation.
Install updates from vendor's website.
Red Hat Enterprise Linux Server from RHUI: 7.0
Red Hat Enterprise Linux for Power, little endian - Extended Update Support: 7.2 - 7.3
Red Hat Enterprise Linux EUS Compute Node: 7.2 - 7.3
Red Hat Enterprise Linux for Power, big endian - Extended Update Support: 7.2 - 7.3
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support: 7.2 - 7.3
Red Hat Enterprise Linux Server - Extended Update Support: 7.2 - 7.3
Red Hat Enterprise Linux Server - TUS: 7.2 - 7.3
Red Hat Enterprise Linux Server - AUS: 7.2 - 7.3
Red Hat Enterprise Linux for Power, little endian: 7
Red Hat Enterprise Linux for Power, big endian: 7
Red Hat Enterprise Linux for IBM z Systems: 7
Red Hat Enterprise Linux for Scientific Computing: 7
Red Hat Enterprise Linux Desktop: 7
Red Hat Enterprise Linux Workstation: 7
Red Hat Enterprise Linux Server: 7
openssl (Red Hat package): before 1.0.1e-51.el7_2.5
CPE2.3https://access.redhat.com/errata/RHSA-2016:0722
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU89734
Risk: Medium
CVSSv4.0: 6.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2016-2842
CWE-ID:
CWE-119 - Memory corruption
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a doapr_outch function in crypto/bio/b_print.c in OpenSSL does not verify that a certain memory allocation succeeds. A remote attacker can cause a denial of service (out-of-bounds write or memory consumption) or possibly have unspecified other impact via a long string
MitigationInstall updates from vendor's website.
Red Hat Enterprise Linux Server from RHUI: 7.0
Red Hat Enterprise Linux for Power, little endian - Extended Update Support: 7.2 - 7.3
Red Hat Enterprise Linux EUS Compute Node: 7.2 - 7.3
Red Hat Enterprise Linux for Power, big endian - Extended Update Support: 7.2 - 7.3
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support: 7.2 - 7.3
Red Hat Enterprise Linux Server - Extended Update Support: 7.2 - 7.3
Red Hat Enterprise Linux Server - TUS: 7.2 - 7.3
Red Hat Enterprise Linux Server - AUS: 7.2 - 7.3
Red Hat Enterprise Linux for Power, little endian: 7
Red Hat Enterprise Linux for Power, big endian: 7
Red Hat Enterprise Linux for IBM z Systems: 7
Red Hat Enterprise Linux for Scientific Computing: 7
Red Hat Enterprise Linux Desktop: 7
Red Hat Enterprise Linux Workstation: 7
Red Hat Enterprise Linux Server: 7
openssl (Red Hat package): before 1.0.1e-51.el7_2.5
CPE2.3https://access.redhat.com/errata/RHSA-2016:0722
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.