Buffer overflow in OpenSSL - CVE-2016-2842

 

Buffer overflow in OpenSSL - CVE-2016-2842

Published: May 22, 2024


Vulnerability identifier: #VU89734
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-2842
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a doapr_outch function in crypto/bio/b_print.c in OpenSSL does not verify that a certain memory allocation succeeds. A remote attacker can cause a denial of service (out-of-bounds write or memory consumption) or possibly have unspecified other impact via a long string


Affected software

OpenSSL
Fedora
Red Hat Enterprise Linux Server from RHUI
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - Extended Update Support
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - AUS
Integrated Management Module II (IMM2)
openssl101e
openssl (Red Hat package)
IBM BladeCenter Advanced Management Module

How to mitigate CVE-2016-2842

Install updates from vendor's website.

OpenSSL - update to 1.0.1s
Integrated Management Module II (IMM2) - update to 1AOO74F-5.80
openssl101e - update to 1.0.1e-8.el5
openssl (Red Hat package) - addressed in versions 1.0.1e-42.el6_7.5, 1.0.1e-48.el6_8.1, 1.0.1e-51.el7_2.5
IBM BladeCenter Advanced Management Module - update to 3.66z

External References

Related Security Bulletins