Double free error in Oracle products - CVE-2016-0705

 

Double free error in Oracle products - CVE-2016-0705

Published: December 21, 2016 / Updated: May 1, 2018


Vulnerability identifier: #VU1622
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-0705
CWE-ID: CWE-415
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote unauthenticated attacker to cause DoS condition on the target system.

The weakness exists due to double-free error when parsing DSA private keys. A remote attacker can trigger memory corruption and cause the service to crash.

Affected software

MySQL Server
Oracle Linux
Oracle Solaris
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Power, little endian
Slackware Linux
Fedora
Opensuse
Oracle Communications Session Border Controller
IBM Algo One Core
IBM Cognos Controller
Integrated Data protection Appliance (IDPA)
Data Protection Search
Red Hat Satellite
IBM MQ
IBM BladeCenter Advanced Management Module
IBM Cognos Analytics
IBM Integrated Management Module
Integrated Management Module II (IMM2)
FlashSystem 840 9840-AE1 & 9843-AE1
HPE OneView
Tivoli Network Manager IP Edition
openssl
openssl-solibs
java-1.8.0-ibm (Red Hat package)
java-1.8.0-ibm-demo (Red Hat package)
java-1.8.0-ibm-devel (Red Hat package)
java-1.8.0-ibm-jdbc (Red Hat package)
java-1.8.0-ibm-plugin (Red Hat package)
java-1.8.0-ibm-src (Red Hat package)
FlashSystem 900 9840-AE2 and 9843-AE2
IBM Storwize V5000
IBM Storwize V7000
IBM SAN Volume Controller
IBM Storwize V3500
IBM Storwize V3700
QLogic 8Gb Intelligent Pass-thru Module & SAN Switch Module for BladeCenter
QLogic Virtual Fabric Extension Module for IBM BladeCenter
Flex System FC3171 8Gb SAN Pass-thru
Flex System FC3171 8Gb SAN Switch

How to mitigate CVE-2016-0705

Install update from vendor's website.

IBM Cognos Analytics - update to 11.0.13
IBM Integrated Management Module - update to YUOOH2B-1.5.1
openssl - addressed in versions 0.9.8zh, 1.0.1s
openssl-solibs - addressed in versions 0.9.8zh, 1.0.1s
Integrated Management Module II (IMM2) - update to 1aoo72h-5.60
openssl - addressed in versions 1.0.1k-14.fc22, 1.0.2g-1.fc23, 1.0.2g-2.fc23
FlashSystem 840 9840-AE1 & 9843-AE1 - update to 1.5.2.6-468.155
FlashSystem 900 9840-AE2 and 9843-AE2 - update to 1.6.1.5-515.226
java-1.8.0-ibm (Red Hat package) - addressed in versions 1.8.0.5.20-1jpp.1.el6_10, 1.8.0.5.20-1jpp.1.el7
java-1.8.0-ibm-demo (Red Hat package) - addressed in versions 1.8.0.5.20-1jpp.1.el6_10, 1.8.0.5.20-1jpp.1.el7
java-1.8.0-ibm-devel (Red Hat package) - addressed in versions 1.8.0.5.20-1jpp.1.el6_10, 1.8.0.5.20-1jpp.1.el7
java-1.8.0-ibm-jdbc (Red Hat package) - addressed in versions 1.8.0.5.20-1jpp.1.el6_10, 1.8.0.5.20-1jpp.1.el7
java-1.8.0-ibm-plugin (Red Hat package) - addressed in versions 1.8.0.5.20-1jpp.1.el6_10, 1.8.0.5.20-1jpp.1.el7
java-1.8.0-ibm-src (Red Hat package) - addressed in versions 1.8.0.5.20-1jpp.1.el6_10, 1.8.0.5.20-1jpp.1.el7
HPE OneView - update to 2.00.07
Integrated Data protection Appliance (IDPA) - update to 2.7.8 with DP Search 19.6.6
Tivoli Network Manager IP Edition - addressed in versions 3.9.0.132, 4.1.1.49, 4.2.0.5
IBM BladeCenter Advanced Management Module - update to 3.66u
IBM Storwize V5000 - addressed in versions 7.5.0.8, 7.6.1.3
IBM Storwize V7000 - addressed in versions 7.5.0.8, 7.6.1.3
IBM SAN Volume Controller - addressed in versions 7.5.0.8, 7.6.1.3
IBM Storwize V3500 - addressed in versions 7.5.0.8, 7.6.1.3
IBM Storwize V3700 - addressed in versions 7.5.0.8, 7.6.1.3
QLogic 8Gb Intelligent Pass-thru Module & SAN Switch Module for BladeCenter - update to 7.10.1.38.00
QLogic Virtual Fabric Extension Module for IBM BladeCenter - update to 9.0.3.16.00
Flex System FC3171 8Gb SAN Pass-thru - update to 9.1.8.01.00
Flex System FC3171 8Gb SAN Switch - update to 9.1.8.01.00
Data Protection Search - update to 19.6.6

External References

Related Security Bulletins