Heap overflow in Apple Inc. products - CVE-2016-2105

 

Heap overflow in Apple Inc. products - CVE-2016-2105

Published: September 23, 2016 / Updated: January 13, 2017


Vulnerability identifier: #VU640
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-2105
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to cause heap overflow on the target system.

The weakness is caused by insufficient input validation. By sending a great deal of input data attackers are able to cause overflow of the EVP_EncodeUpdate() function used for binary data encoding.

Successful exploitation of the vulnerability may result in heap overflow on the vulnerable system.

Affected software


Oracle Exalogic Infrastructure
Oracle Enterprise Manager Ops Center
OpenSSL
Oracle Life Sciences Data Hub
Oracle Agile Engineering Data Management
SnapDrive for Unix
SnapDrive for Windows
Integrated Management Module II (IMM2)
Oracle VM Server for x86
NetWorker
Oracle Secure Global Desktop
Oracle Linux
Oracle Solaris
macOS
Amazon Linux AMI
Gentoo Linux
Fedora
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Server from RHUI
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux Server - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
SUSE Linux
Slackware Linux
Opensuse
Oracle VM VirtualBox
Oracle Commerce Guided Search
Oracle E-Business Suite
PeopleSoft Enterprise PeopleTools
Oracle Access Manager
openssl (Alpine package)
Data ONTAP operating in 7-Mode
openssl101e
openssl (Red Hat package)
openssl
mingw-openssl
dev-libs/openssl

How to mitigate CVE-2016-2105

Update 1.0.1 to 1.0.1t.
Update 1.0.2 to 1.0.2h.

openssl (Alpine package) - update to 1.0.2h-r3
SnapDrive for Unix - update to 5.3.1
SnapDrive for Windows - update to 7.1.4
Data ONTAP operating in 7-Mode - update to 8.2.5
Integrated Management Module II (IMM2) - update to 1AOO74F-5.80
openssl101e - update to 1.0.1e-8.el5
openssl (Red Hat package) - addressed in versions 1.0.1e-42.el6_7.5, 1.0.1e-48.el6_8.1, 1.0.1e-51.el7_2.5
openssl - addressed in versions 1.0.1k-15.fc22, 1.0.2h-1.fc23, 1.0.2h-1.fc24
mingw-openssl - update to 1.0.2h-1.el7
dev-libs/openssl - update to 1.0.2j
NetWorker - update to 19.10.0.0

External References

Related Security Bulletins