Denial of service in OpenSSL - CVE-2016-6305
Published: September 23, 2016
Vulnerability identifier: #VU645
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-6305
CWE-ID: CWE-371
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote authenticated user to trigger denial of service on the target system.
The weakness exists due to state error. By sendidng specially crafted files attackers can cause a flaw in SSL_peek() that may lead to the affected service hanging.
Successful exploitation of the vulnerability results in denial of service on the vulnerable system.
The weakness exists due to state error. By sendidng specially crafted files attackers can cause a flaw in SSL_peek() that may lead to the affected service hanging.
Successful exploitation of the vulnerability results in denial of service on the vulnerable system.
Affected software
OpenSSL
Amazon Linux AMI
Gentoo Linux
Slackware Linux
SnapDrive for Windows
Network Advisor
Data ONTAP operating in 7-Mode
openssl
openssl-solibs
dev-libs/openssl
Puppet Agent
FOS Firmware
Puppet Enterprise
Amazon Linux AMI
Gentoo Linux
Slackware Linux
SnapDrive for Windows
Network Advisor
Data ONTAP operating in 7-Mode
openssl
openssl-solibs
dev-libs/openssl
Puppet Agent
FOS Firmware
Puppet Enterprise
How to mitigate CVE-2016-6305
Update to 1.1.0a.
SnapDrive for Windows - update to 7.1.4
Data ONTAP operating in 7-Mode - update to 8.2.5
openssl - addressed in versions 1.0.1u, 1.0.2i
openssl-solibs - addressed in versions 1.0.1u, 1.0.2i
dev-libs/openssl - update to 1.0.2j
Puppet Agent - update to 1.7.1
FOS Firmware - addressed in versions 7.4.2a, 8.01c
Network Advisor - update to 14.0.2
Puppet Enterprise - update to 2016.4.0
Data ONTAP operating in 7-Mode - update to 8.2.5
openssl - addressed in versions 1.0.1u, 1.0.2i
openssl-solibs - addressed in versions 1.0.1u, 1.0.2i
dev-libs/openssl - update to 1.0.2j
Puppet Agent - update to 1.7.1
FOS Firmware - addressed in versions 7.4.2a, 8.01c
Network Advisor - update to 14.0.2
Puppet Enterprise - update to 2016.4.0