Memory corruption in Apple Inc. products - CVE-2016-2108
Published: September 23, 2016 / Updated: February 21, 2019
Vulnerability identifier: #VU638
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-2108
CWE-ID: CWE-120
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to cause memory corruption on the target system.
The weakness exists due to buffer underflow with an out-of-bounds write in i2c_ASN1_INTEGER. As ASN.1 parser (specifically, d2i_ASN1_TYPE) can misinterpret a large universal tag as a negative zero value, attacker may easily corrupt memory.
Successful exploitation of the vulnerability will allow a malicious user to trigger memory corruption on the vulnerable system.
The weakness exists due to buffer underflow with an out-of-bounds write in i2c_ASN1_INTEGER. As ASN.1 parser (specifically, d2i_ASN1_TYPE) can misinterpret a large universal tag as a negative zero value, attacker may easily corrupt memory.
Successful exploitation of the vulnerability will allow a malicious user to trigger memory corruption on the vulnerable system.
Affected software
Oracle Exalogic Infrastructure
OpenSSL
Oracle Linux
Oracle Solaris
macOS
Gentoo Linux
Amazon Linux AMI
Fedora
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Server from RHUI
Red Hat Enterprise Linux Server - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - AUS
SUSE Linux
Slackware Linux
Opensuse
ProtecTIER Enterprise Edition (PID 5639-PTA) - TS7650G
ProtecTIER Appliance Edition (PID 5639-PTB) - TS7650AP1
ProtecTIER Entry Edition (PID 5639-PTC) - TS7610 / TS7620
ProtecTIER Gateway for System Z (PID 5639-FPA)
IBM Observability with Instana
IBM Cloud Pak for Business Automation
iDRAC6
iDRAC8
iDRAC7
Storage Defender - Resiliency Service
SnapDrive for Unix
SnapDrive for Windows
HPE IceWall SSO Agent Option
Integrated Management Module II (IMM2)
Network Advisor
Data ONTAP operating in 7-Mode
openssl101e
openssl (Red Hat package)
openssl
mingw-openssl
dev-libs/openssl
Integrated Data protection Appliance (IDPA)
Data Protection Search
FOS Firmware
OpenSSL
Oracle Linux
Oracle Solaris
macOS
Gentoo Linux
Amazon Linux AMI
Fedora
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Server from RHUI
Red Hat Enterprise Linux Server - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - AUS
SUSE Linux
Slackware Linux
Opensuse
ProtecTIER Enterprise Edition (PID 5639-PTA) - TS7650G
ProtecTIER Appliance Edition (PID 5639-PTB) - TS7650AP1
ProtecTIER Entry Edition (PID 5639-PTC) - TS7610 / TS7620
ProtecTIER Gateway for System Z (PID 5639-FPA)
IBM Observability with Instana
IBM Cloud Pak for Business Automation
iDRAC6
iDRAC8
iDRAC7
Storage Defender - Resiliency Service
SnapDrive for Unix
SnapDrive for Windows
HPE IceWall SSO Agent Option
Integrated Management Module II (IMM2)
Network Advisor
Data ONTAP operating in 7-Mode
openssl101e
openssl (Red Hat package)
openssl
mingw-openssl
dev-libs/openssl
Integrated Data protection Appliance (IDPA)
Data Protection Search
FOS Firmware
How to mitigate CVE-2016-2108
Update 1.0.2 to 1.0.2c.
Update 1.0.1 to 1.0.1c.
Update 1.0.1 to 1.0.1c.
iDRAC6 - addressed in versions 2.85, 3.80
iDRAC8 - update to 2.30.30.30
Storage Defender - Resiliency Service - update to 2.0.14
iDRAC7 - update to 2.30.30.30
SnapDrive for Unix - update to 5.3.1
SnapDrive for Windows - update to 7.1.4
Data ONTAP operating in 7-Mode - update to 8.2.5
Integrated Management Module II (IMM2) - update to 1AOO74F-5.80
openssl101e - update to 1.0.1e-8.el5
openssl (Red Hat package) - addressed in versions 1.0.1e-42.el6_7.5, 1.0.1e-48.el6_8.1, 1.0.1e-51.el7_2.5
openssl - addressed in versions 1.0.1k-15.fc22, 1.0.2h-1.fc23, 1.0.2h-1.fc24
mingw-openssl - update to 1.0.2h-1.el7
dev-libs/openssl - update to 1.0.2j
IBM Observability with Instana - update to 1.0.295
Integrated Data protection Appliance (IDPA) - update to 2.7.8 with DP Search 19.6.6
FOS Firmware - addressed in versions 7.4.2, 8.1.0c
Network Advisor - update to 14.0.2
Data Protection Search - update to 19.6.6
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF037, 24.0.0-IF003
iDRAC8 - update to 2.30.30.30
Storage Defender - Resiliency Service - update to 2.0.14
iDRAC7 - update to 2.30.30.30
SnapDrive for Unix - update to 5.3.1
SnapDrive for Windows - update to 7.1.4
Data ONTAP operating in 7-Mode - update to 8.2.5
Integrated Management Module II (IMM2) - update to 1AOO74F-5.80
openssl101e - update to 1.0.1e-8.el5
openssl (Red Hat package) - addressed in versions 1.0.1e-42.el6_7.5, 1.0.1e-48.el6_8.1, 1.0.1e-51.el7_2.5
openssl - addressed in versions 1.0.1k-15.fc22, 1.0.2h-1.fc23, 1.0.2h-1.fc24
mingw-openssl - update to 1.0.2h-1.el7
dev-libs/openssl - update to 1.0.2j
IBM Observability with Instana - update to 1.0.295
Integrated Data protection Appliance (IDPA) - update to 2.7.8 with DP Search 19.6.6
FOS Firmware - addressed in versions 7.4.2, 8.1.0c
Network Advisor - update to 14.0.2
Data Protection Search - update to 19.6.6
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF037, 24.0.0-IF003
External References
- https://www.openssl.org/news/secadv/20160503.txt
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- https://support.apple.com/cs-cz/HT206903
Related Security Bulletins
- SUSE Linux update for openssl
- Remote code execution in Dell EMC iDRAC
- Red Hat update for openssl
- SUSE Linux update for openssl
- SUSE Linux update for openssl
- OpenSUSE Linux update for compat-openssl098
- OpenSUSE Linux update for openssl
- OpenSUSE Linux update for libopenssl0_9_8
- SUSE Linux update for openssl
- SUSE Linux update for openssl
- SUSE Linux update for openssl1
- Amazon Linux AMI update for openssl
- Slackware Linux update for openssl
- Memory corruption in IBM Network Advisor
- Memory corruption in HPE IceWall Products using OpenSSL
- Multiple vulnerabilities in Multiple N series Products
- Memory corruption in IBM ProtecTIER
- Multiple vulnerabilities in IBM Integrated Management Module II
- Gentoo update for OpenSSL
- Fedora 23 update for openssl
- Fedora 22 update for openssl
- Fedora 24 update for openssl
- Fedora EPEL 7 update for mingw-openssl
- Fedora EPEL 5 update for openssl101e
- Red Hat Enterprise Linux 7 update for openssl
- Red Hat Enterprise Linux 6 update for openssl
- Red Hat Enterprise Linux 6 update for openssl
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in Dell Data Protection Search
- Multiple vulnerabilities in IBM Observability with Instana (OnPrem)
- Multiple vulnerabilities in IBM Storage Defender - Resiliency Service