Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2016-2176

Published: May 5, 2016Last modified: November 9, 2023

Description

The X509_NAME_oneline function in crypto/x509/x509_obj.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to obtain sensitive information from process stack memory or cause a denial of service (buffer over-read) via crafted EBCDIC ASN.1 data.

Severity score breakdown

ParameterValue
Base score8.2
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityLOW
Integrity impactNONE
Availability impactHIGH
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSopensslNot affected (3.0.10-r0)
StreamopensslNot affected (3.1.2-r0)

References

ON THIS PAGE