Out-of-bounds write in OpenSSL - CVE-2016-2182

 

Out-of-bounds write in OpenSSL - CVE-2016-2182

Published: December 21, 2016 / Updated: March 6, 2023


Vulnerability identifier: #VU1968
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-2182
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a boundary error within the BN_bn2dec() function in crypto/bn/bn_print.c in OpenSSL. A remote attacker can send specially crafted data to the server, trigger an out-of-bounds write and execute arbitrary code on the target system.


Affected software

OpenSSL
FlashSystem 900 9840-AE2 and 9843-AE2
FOS Firmware
FlashSystem 840 9840-AE1 & 9843-AE1
SnapDrive for Windows
Network Advisor
Arch Linux
Fedora
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - Extended Update Support
Slackware Linux
Opensuse
openssl (Alpine package)
Data ONTAP operating in 7-Mode
lib32-openssl
openssl101e
openssl (Red Hat package)
openssl
openssl-solibs
Puppet Agent
NetWorker
IBM Cloud Pak for Business Automation
Puppet Enterprise

How to mitigate CVE-2016-2182

Install update from vendor's website.

OpenSSL - addressed in versions 1.0.1u, 1.0.2i
openssl (Alpine package) - update to 1.0.2h-r3
SnapDrive for Windows - update to 7.1.4
Data ONTAP operating in 7-Mode - update to 8.2.5
lib32-openssl - update to 1
openssl101e - update to 1.0.1e-9.el5
openssl (Red Hat package) - addressed in versions 1.0.1e-48.el6_8.3, 1.0.1e-51.el7_2.7
openssl - addressed in versions 1.0.1u, 1.0.2i
openssl-solibs - addressed in versions 1.0.1u, 1.0.2i
openssl - update to 1.0.2.i-1
openssl - addressed in versions 1.0.2j-1.fc23, 1.0.2j-1.fc24, 1.0.2j-1.fc25
Puppet Agent - update to 1.7.1
FOS Firmware - addressed in versions 7.4.2a, 8.01c
Network Advisor - update to 14.0.2
NetWorker - update to 19.10.0.0
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF037, 24.0.0-IF003
Puppet Enterprise - update to 2016.4.0

External References

Related Security Bulletins