Denial of service in OpenSSL - CVE-2016-8610
Published: October 24, 2016 / Updated: March 30, 2018
Vulnerability identifier: #VU1083
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-8610
CWE-ID: CWE-388
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote unauthenticated user to exhaust memory on the target system.
The weakness is due to improper handling of certain packets by the ssl3_read_bytes() function in 'ssl/s3_pkt.c.
By sending a flood of SSL3_AL_WARNING alerts during the SSL handshake, a remote attacker can consume excessive CPU resources that may lead to OpenSSL library being unavailable.
Successful exploitation of the vulnerability results in denial of service on the vulnerable system.
The weakness is due to improper handling of certain packets by the ssl3_read_bytes() function in 'ssl/s3_pkt.c.
By sending a flood of SSL3_AL_WARNING alerts during the SSL handshake, a remote attacker can consume excessive CPU resources that may lead to OpenSSL library being unavailable.
Successful exploitation of the vulnerability results in denial of service on the vulnerable system.
Affected software
OpenSSL
Amazon Linux AMI
Fedora
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Server for ARM
Red Hat Enterprise Linux Server - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - AUS
SUSE Linux
Ubuntu
Opensuse
openssl101e
openssl (Red Hat package)
openssl
gnutls (Red Hat package)
EMC Atmos
EMC Cloud Tiering Appliance
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
NetWorker
Amazon Linux AMI
Fedora
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Server for ARM
Red Hat Enterprise Linux Server - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - AUS
SUSE Linux
Ubuntu
Opensuse
openssl101e
openssl (Red Hat package)
openssl
gnutls (Red Hat package)
EMC Atmos
EMC Cloud Tiering Appliance
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
NetWorker
How to mitigate CVE-2016-8610
Update to version 1.0.2j, 1.1.0b.
openssl101e - update to 1.0.1e-10.el5
openssl (Red Hat package) - addressed in versions 1.0.1e-48.el6_8.4, 1.0.1e-60.el7_3.1
openssl - addressed in versions 1.0.2k-1.fc24, 1.0.2k-1.fc25
EMC Atmos - addressed in versions 2.4.2 HF505, 2.4.3 HF505
gnutls (Red Hat package) - update to 2.12.23-21.el6
Dell EMC Unity VSA Operating Environment (OE) - update to 5.0.0.0.5.116
Dell EMC Unity Operating Environment (OE) - update to 5.0.0.0.5.116
EMC Cloud Tiering Appliance - update to 12.1.0.65
NetWorker - update to 19.10.0.0
openssl (Red Hat package) - addressed in versions 1.0.1e-48.el6_8.4, 1.0.1e-60.el7_3.1
openssl - addressed in versions 1.0.2k-1.fc24, 1.0.2k-1.fc25
EMC Atmos - addressed in versions 2.4.2 HF505, 2.4.3 HF505
gnutls (Red Hat package) - update to 2.12.23-21.el6
Dell EMC Unity VSA Operating Environment (OE) - update to 5.0.0.0.5.116
Dell EMC Unity Operating Environment (OE) - update to 5.0.0.0.5.116
EMC Cloud Tiering Appliance - update to 12.1.0.65
NetWorker - update to 19.10.0.0
External References
Related Security Bulletins
- Red Hat update for Apache HTTP Server
- Ubuntu update for GnuTLS
- Ubuntu update for GnuTLS
- Ubuntu update for OpenSSL
- Amazon Linux AMI update for gnutls
- Amazon Linux AMI update for openssl
- SUSE Linux update for gnutls
- OpenSUSE Linux update for gnutls
- SUSE Linux update for gnutls
- SUSE Linux update for openssl
- OpenSUSE Linux update for compat-openssl098
- Multiple vulnerabilities in Dell EMC Unity Family
- Multiple vulnerabilities in Dell EMC Atmos
- Multiple vulnerabilities in Dell EMC Cloud Tiering Appliance Family
- Multiple vulnerabilities in Dell Networker
- Fedora 25 update for openssl
- Fedora 24 update for openssl
- Fedora EPEL 5 update for openssl101e
- Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7 update for openssl
- Red Hat Enterprise Linux 6 update for gnutls