Excessive memory allocation in Apple Inc. products - CVE-2016-2109
Published: September 23, 2016 / Updated: January 13, 2017
Vulnerability identifier: #VU641
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-2109
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to cause excessive memory allocation on the target system.
The weakness exists during reading ASN.1 data by d2i_CMS_bio() function. A short invalid encoding leads to distribution of large amounts of memory for excessive resources or exhausting memory.
Successful exploitation of the vulnerability may result in excessive memory allocation.
The weakness exists during reading ASN.1 data by d2i_CMS_bio() function. A short invalid encoding leads to distribution of large amounts of memory for excessive resources or exhausting memory.
Successful exploitation of the vulnerability may result in excessive memory allocation.
Affected software
Oracle Exalogic Infrastructure
Oracle Enterprise Manager Ops Center
OpenSSL
Oracle Life Sciences Data Hub
Oracle Agile Engineering Data Management
SnapDrive for Unix
SnapDrive for Windows
Integrated Management Module II (IMM2)
Oracle VM Server for x86
NetWorker
Oracle Linux
Oracle Solaris
macOS
Amazon Linux AMI
Gentoo Linux
Fedora
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Server from RHUI
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux Server - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
SUSE Linux
Slackware Linux
Opensuse
Oracle VM VirtualBox
Oracle Commerce Guided Search
Oracle E-Business Suite
PeopleSoft Enterprise PeopleTools
Oracle Access Manager
openssl (Alpine package)
Data ONTAP operating in 7-Mode
openssl101e
openssl (Red Hat package)
dev-libs/openssl
Oracle Enterprise Manager Ops Center
OpenSSL
Oracle Life Sciences Data Hub
Oracle Agile Engineering Data Management
SnapDrive for Unix
SnapDrive for Windows
Integrated Management Module II (IMM2)
Oracle VM Server for x86
NetWorker
Oracle Linux
Oracle Solaris
macOS
Amazon Linux AMI
Gentoo Linux
Fedora
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Server from RHUI
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux Server - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
SUSE Linux
Slackware Linux
Opensuse
Oracle VM VirtualBox
Oracle Commerce Guided Search
Oracle E-Business Suite
PeopleSoft Enterprise PeopleTools
Oracle Access Manager
openssl (Alpine package)
Data ONTAP operating in 7-Mode
openssl101e
openssl (Red Hat package)
dev-libs/openssl
How to mitigate CVE-2016-2109
Update 1.0.1 to 1.01t.
Update 1.0.2. to 1.0.2h.
Update 1.0.2. to 1.0.2h.
openssl (Alpine package) - update to 1.0.2h-r3
SnapDrive for Unix - update to 5.3.1
SnapDrive for Windows - update to 7.1.4
Data ONTAP operating in 7-Mode - update to 8.2.5
Integrated Management Module II (IMM2) - update to 1AOO74F-5.80
openssl101e - update to 1.0.1e-8.el5
openssl (Red Hat package) - addressed in versions 1.0.1e-42.el6_7.5, 1.0.1e-48.el6_8.1, 1.0.1e-51.el7_2.5
dev-libs/openssl - update to 1.0.2j
NetWorker - update to 19.10.0.0
SnapDrive for Unix - update to 5.3.1
SnapDrive for Windows - update to 7.1.4
Data ONTAP operating in 7-Mode - update to 8.2.5
Integrated Management Module II (IMM2) - update to 1AOO74F-5.80
openssl101e - update to 1.0.1e-8.el5
openssl (Red Hat package) - addressed in versions 1.0.1e-42.el6_7.5, 1.0.1e-48.el6_8.1, 1.0.1e-51.el7_2.5
dev-libs/openssl - update to 1.0.2j
NetWorker - update to 19.10.0.0
External References
- https://www.openssl.org/news/secadv/20160503.txt
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html
- http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
- https://support.apple.com/cs-cz/HT206903
Related Security Bulletins
- Excessive memory allocation in OpenSSL
- SUSE Linux update for openssl
- SUSE Linux update for openssl
- OpenSUSE Linux update for compat-openssl098
- OpenSUSE Linux update for openssl
- OpenSUSE Linux update for libopenssl0_9_8
- SUSE Linux update for openssl
- SUSE Linux update for openssl
- SUSE Linux update for openssl1
- Excessive memory allocation in openssl (Alpine package)
- Amazon Linux AMI update for openssl
- Slackware Linux update for openssl
- Multiple vulnerabilities in Multiple N series Products
- Multiple vulnerabilities in IBM Integrated Management Module II
- Multiple vulnerabilities in Dell Networker
- Gentoo update for OpenSSL
- Fedora EPEL 5 update for openssl101e
- Red Hat Enterprise Linux 7 update for openssl
- Red Hat Enterprise Linux 6 update for openssl
- Red Hat Enterprise Linux 6 update for openssl