Out-of-bounds read in OpenSSL - CVE-2016-2180
Published: August 13, 2016 / Updated: March 6, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary condition within the TS_OBJ_print_bio() function in crypto/ts/ts_lib.c in the X.509 Public Key Infrastructure Time-Stamp Protocol (TSP) implementation in OpenSSL. A remote attacker can perform a denial of service (DoS) attack via a crafted time-stamp file that is mishandled by the "openssl ts" command.
Affected software
Arch Linux
Gentoo Linux
Fedora
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Slackware Linux
Opensuse
openssl (Alpine package)
Data ONTAP operating in 7-Mode
lib32-openssl
openssl101e
openssl (Red Hat package)
openssl-solibs
openssl
dev-libs/openssl
SnapDrive for Windows
Network Advisor
Puppet Agent
FOS Firmware
NetWorker
Puppet Enterprise
How to mitigate CVE-2016-2180
openssl (Alpine package) - update to 1.0.1t-r2
SnapDrive for Windows - update to 7.1.4
Data ONTAP operating in 7-Mode - update to 8.2.5
lib32-openssl - update to 1
openssl101e - update to 1.0.1e-9.el5
openssl (Red Hat package) - addressed in versions 1.0.1e-48.el6_8.3, 1.0.1e-51.el7_2.7
openssl-solibs - addressed in versions 1.0.1u, 1.0.2i
openssl - addressed in versions 1.0.1u, 1.0.2i
openssl - update to 1.0.2.i-1
dev-libs/openssl - update to 1.0.2j
openssl - addressed in versions 1.0.2j-1.fc23, 1.0.2j-1.fc24, 1.0.2j-1.fc25
Puppet Agent - update to 1.7.1
FOS Firmware - addressed in versions 7.4.2a, 8.01c
Network Advisor - update to 14.0.2
NetWorker - update to 19.10.0.0
Puppet Enterprise - update to 2016.4.0
External References
Related Security Bulletins
- Multiple vulnerabilities in OpenSSL
- openSUSE update for openssl-steam
- Out-of-bounds memory read in openssl (Alpine package)
- Multiple vulnerabilities in IBM FOS Firmware
- Multiple vulnerabilities in OpenSSL
- Multiple vulnerabilities in Multiple N series Products
- Multiple vulnerabilities in Dell Networker
- Gentoo update for OpenSSL
- Slackware Linux update for openssl
- Arch Linux update for lib32-openssl
- Arch Linux update for openssl
- Fedora 24 update for openssl
- Fedora 23 update for openssl
- Fedora 25 update for openssl
- Fedora EPEL 5 update for openssl101e
- Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7 update for openssl
- Puppet Enterprise and Puppet Agent update for OpenSSL