Integer overflow in ssl3_get_client_hello() in Oracle products - CVE-2016-2177

 

Integer overflow in ssl3_get_client_hello() in Oracle products - CVE-2016-2177

Published: June 24, 2016 / Updated: February 27, 2025


Vulnerability identifier: #VU24
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-2177
CWE-ID: CWE-494
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause denial of service conditions on the target system.
The vulnerability exists due to a boundary error in ssl3_get_client_hello() function. A remote attacker can cause integer overflow by sending specially crafted data and crash the service.
Successful exploitation of this vulnerability may cause the target service to crash.

Affected software

OpenSSL
Oracle VM Server for x86
NetWorker
Oracle Linux
Oracle Solaris
Arch Linux
Gentoo Linux
Fedora
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Server - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Ubuntu
Slackware Linux
Opensuse
Oracle VM VirtualBox
Energy Expert
Citect Anywhere
PlantStruxure PES
EcoStruxure Modicon Builder
StruxureWare Power Monitoring Expert
EcoStruxure Power SCADA Operations
Vijeo Historian
CitectHistorian
CitectSCADA
SCADA Expert Vijeo Citect
EcoStruxure Power Monitoring Expert
FlashSystem 840 9840-AE1 & 9843-AE1
SnapDrive for Windows
Integrated Management Module II (IMM2)
IBM Integrated Management Module
Network Advisor
FlashSystem 900 9840-AE2 and 9843-AE2
FOS Firmware
openssl (Alpine package)
Data ONTAP operating in 7-Mode
lib32-openssl
openssl101e
openssl (Red Hat package)
openssl
openssl-solibs
dev-libs/openssl
Puppet Agent
IBM Storwize V5000
IBM Storwize V3500
IBM Storwize V3700
IBM FlashSystem V9000
IBM Storwize V7000
Puppet Enterprise

How to mitigate CVE-2016-2177

The vendor has issued a source code fix, available at:

https://github.com/openssl/openssl/commit/a004e72b95835136d3f1ea90517f706c24c03da7

openssl (Alpine package) - update to 1.0.1t-r1
SnapDrive for Windows - update to 7.1.4
Data ONTAP operating in 7-Mode - update to 8.2.5
Integrated Management Module II (IMM2) - update to 1AOO76I-6.00
lib32-openssl - update to 1
openssl101e - update to 1.0.1e-9.el5
openssl (Red Hat package) - addressed in versions 1.0.1e-48.el6_8.3, 1.0.1e-51.el7_2.7
openssl - addressed in versions 1.0.1u, 1.0.2i
openssl-solibs - addressed in versions 1.0.1u, 1.0.2i
openssl - update to 1.0.2.i-1
dev-libs/openssl - update to 1.0.2j
openssl - addressed in versions 1.0.2j-1.fc23, 1.0.2j-1.fc24, 1.0.2j-1.fc25
Puppet Agent - update to 1.7.1
IBM Integrated Management Module - update to 1.52
FOS Firmware - addressed in versions 7.4.2a, 8.01c
IBM Storwize V5000 - addressed in versions 7.6.1.7, 7.7.1.6, 7.8.0.2, 7.8.1.0
IBM Storwize V3500 - addressed in versions 7.6.1.7, 7.7.1.6, 7.8.0.2, 7.8.1.0
IBM Storwize V3700 - addressed in versions 7.6.1.7, 7.7.1.6, 7.8.0.2, 7.8.1.0
IBM FlashSystem V9000 - addressed in versions 7.6.1.7, 7.7.1.6, 7.8.0.2, 7.8.1.0
IBM Storwize V7000 - addressed in versions 7.6.1.7, 7.7.1.6, 7.8.0.2, 7.8.1.0
Network Advisor - update to 14.0.2
NetWorker - update to 19.10.0.0
Puppet Enterprise - update to 2016.4.0

External References

Related Security Bulletins