Denial of service in OpenSSL - CVE-2016-8610

 

Denial of service in OpenSSL - CVE-2016-8610

Published: October 24, 2016 / Updated: March 30, 2018


Vulnerability identifier: #VU1083
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-8610
CWE-ID: CWE-388
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote unauthenticated user to exhaust memory on the target system.
The weakness is due to improper handling of certain packets by the ssl3_read_bytes() function in 'ssl/s3_pkt.c.
By sending a flood of SSL3_AL_WARNING alerts during the SSL handshake, a remote attacker can consume excessive CPU resources that may lead to OpenSSL library being unavailable.
Successful exploitation of the vulnerability results in denial of service on the vulnerable system.

Affected software

OpenSSL
Amazon Linux AMI
Fedora
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Server for ARM
Red Hat Enterprise Linux Server - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - AUS
SUSE Linux
Ubuntu
Opensuse
openssl101e
openssl (Red Hat package)
openssl
gnutls (Red Hat package)
EMC Atmos
EMC Cloud Tiering Appliance
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
NetWorker

How to mitigate CVE-2016-8610

Update to version 1.0.2j, 1.1.0b.

openssl101e - update to 1.0.1e-10.el5
openssl (Red Hat package) - addressed in versions 1.0.1e-48.el6_8.4, 1.0.1e-60.el7_3.1
openssl - addressed in versions 1.0.2k-1.fc24, 1.0.2k-1.fc25
EMC Atmos - addressed in versions 2.4.2 HF505, 2.4.3 HF505
gnutls (Red Hat package) - update to 2.12.23-21.el6
Dell EMC Unity VSA Operating Environment (OE) - update to 5.0.0.0.5.116
Dell EMC Unity Operating Environment (OE) - update to 5.0.0.0.5.116
EMC Cloud Tiering Appliance - update to 12.1.0.65
NetWorker - update to 19.10.0.0

External References

Related Security Bulletins