Resource exhaustion in OpenSSL - CVE-2016-6304

 

Resource exhaustion in OpenSSL - CVE-2016-6304

Published: September 23, 2016 / Updated: October 6, 2022


Vulnerability identifier: #VU646
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-6304
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper resource management in OCSP stapling implementation in OpenSSL. A remote attacker can multiple requests with a large OCSP Status Request extension and consume all available memory on the system.


Affected software

OpenSSL
Amazon Linux AMI
Arch Linux
Gentoo Linux
Fedora
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux Server - Extended Update Support
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Slackware Linux
Opensuse
FlashSystem 900 9840-AE2 and 9843-AE2
FOS Firmware
FlashSystem 840 9840-AE1 & 9843-AE1
SnapDrive for Windows
Network Advisor
Data ONTAP operating in 7-Mode
lib32-openssl
openssl (Red Hat package)
openssl101e
openssl
openssl-solibs
dev-libs/openssl
Puppet Agent
IBM Storwize V5000
IBM Storwize V3700
IBM Storwize V7000
IBM Storwize V3500
IBM FlashSystem V9000
NetWorker
Puppet Enterprise

How to mitigate CVE-2016-6304

Install update from vendor's website.

OpenSSL - addressed in versions 1.0.1u, 1.0.2i, 1.1.0a
SnapDrive for Windows - update to 7.1.4
Data ONTAP operating in 7-Mode - update to 8.2.5
lib32-openssl - update to 1
openssl (Red Hat package) - addressed in versions 1.0.0-20.el6_2.9, 1.0.0-27.el6_4.6, 1.0.1e-16.el6_5.17, 1.0.1e-30.el6_6.13, 1.0.1e-42.el6_7.6, 1.0.1e-48.el6_8.3, 1.0.1e-51.el7_2.7
openssl101e - update to 1.0.1e-9.el5
openssl - addressed in versions 1.0.1u, 1.0.2i
openssl-solibs - addressed in versions 1.0.1u, 1.0.2i
openssl - update to 1.0.2.i-1
dev-libs/openssl - update to 1.0.2j
openssl - addressed in versions 1.0.2j-1.fc23, 1.0.2j-1.fc24, 1.0.2j-1.fc25
Puppet Agent - update to 1.7.1
FOS Firmware - addressed in versions 7.4.2a, 8.01c
IBM Storwize V5000 - addressed in versions 7.6.1.7, 7.7.1.6, 7.8.0.2, 7.8.1.0
IBM Storwize V3700 - addressed in versions 7.6.1.7, 7.7.1.6, 7.8.0.2, 7.8.1.0
IBM Storwize V7000 - addressed in versions 7.6.1.7, 7.7.1.6, 7.8.0.2, 7.8.1.0
IBM Storwize V3500 - addressed in versions 7.6.1.7, 7.7.1.6, 7.8.0.2, 7.8.1.0
IBM FlashSystem V9000 - addressed in versions 7.6.1.7, 7.7.1.6, 7.8.0.2, 7.8.1.0
Network Advisor - update to 14.0.2
NetWorker - update to 19.10.0.0
Puppet Enterprise - update to 2016.4.0

External References

Related Security Bulletins