Memory corruption in Apple Inc. products - CVE-2016-2108

 

Memory corruption in Apple Inc. products - CVE-2016-2108

Published: September 23, 2016 / Updated: February 21, 2019


Vulnerability identifier: #VU638
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-2108
CWE-ID: CWE-120
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to cause memory corruption on the target system.

The weakness exists due to buffer underflow with an out-of-bounds write in i2c_ASN1_INTEGER. As ASN.1 parser (specifically, d2i_ASN1_TYPE) can misinterpret a large universal tag as a negative zero value, attacker may easily corrupt memory.

Successful exploitation of the vulnerability will allow a malicious user to trigger memory corruption on the vulnerable system.

Affected software

Oracle Exalogic Infrastructure
OpenSSL
Oracle Linux
Oracle Solaris
macOS
Gentoo Linux
Amazon Linux AMI
Fedora
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Server from RHUI
Red Hat Enterprise Linux Server - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - AUS
SUSE Linux
Slackware Linux
Opensuse
ProtecTIER Enterprise Edition (PID 5639-PTA) - TS7650G
ProtecTIER Appliance Edition (PID 5639-PTB) - TS7650AP1
ProtecTIER Entry Edition (PID 5639-PTC) - TS7610 / TS7620
ProtecTIER Gateway for System Z (PID 5639-FPA)
IBM Observability with Instana
IBM Cloud Pak for Business Automation
iDRAC6
iDRAC8
iDRAC7
Storage Defender - Resiliency Service
SnapDrive for Unix
SnapDrive for Windows
HPE IceWall SSO Agent Option
Integrated Management Module II (IMM2)
Network Advisor
Data ONTAP operating in 7-Mode
openssl101e
openssl (Red Hat package)
openssl
mingw-openssl
dev-libs/openssl
Integrated Data protection Appliance (IDPA)
Data Protection Search
FOS Firmware

How to mitigate CVE-2016-2108

Update 1.0.2 to 1.0.2c.
Update 1.0.1 to 1.0.1c.

iDRAC6 - addressed in versions 2.85, 3.80
iDRAC8 - update to 2.30.30.30
Storage Defender - Resiliency Service - update to 2.0.14
iDRAC7 - update to 2.30.30.30
SnapDrive for Unix - update to 5.3.1
SnapDrive for Windows - update to 7.1.4
Data ONTAP operating in 7-Mode - update to 8.2.5
Integrated Management Module II (IMM2) - update to 1AOO74F-5.80
openssl101e - update to 1.0.1e-8.el5
openssl (Red Hat package) - addressed in versions 1.0.1e-42.el6_7.5, 1.0.1e-48.el6_8.1, 1.0.1e-51.el7_2.5
openssl - addressed in versions 1.0.1k-15.fc22, 1.0.2h-1.fc23, 1.0.2h-1.fc24
mingw-openssl - update to 1.0.2h-1.el7
dev-libs/openssl - update to 1.0.2j
IBM Observability with Instana - update to 1.0.295
Integrated Data protection Appliance (IDPA) - update to 2.7.8 with DP Search 19.6.6
FOS Firmware - addressed in versions 7.4.2, 8.1.0c
Network Advisor - update to 14.0.2
Data Protection Search - update to 19.6.6
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF037, 24.0.0-IF003

External References

Related Security Bulletins