CVE-2016-0705Improper Restriction of Operations within the Bounds of a Memory Buffer in Openssl

Severity
9.8CRITICALNVD
OSV5.1
EPSS
21.8%
top 4.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 3
Latest updateNov 7

Description

Double free vulnerability in the dsa_priv_decode function in crypto/dsa/dsa_ameth.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a malformed DSA private key.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages9 packages

debiandebian/openssl< openssl 1.0.2g-1 (bookworm)
Debianopenssl/openssl< 1.0.2g-1+3
Ubuntuopenssl/openssl< 1.0.1f-1ubuntu2.18
NVDopenssl/openssl26 versions+25
NVDoracle/mysql5.6.05.6.29+1

Also affects: Debian Linux 7.0, 8.0, Ubuntu Linux 12.04, 14.04, 15.10

Patches

🔴Vulnerability Details

3
GHSA
GHSA-jq9m-v5x9-ppg9: Double free vulnerability in the dsa_priv_decode function in crypto/dsa/dsa_ameth2022-05-14
OSV
CVE-2016-0705: Double free vulnerability in the dsa_priv_decode function in crypto/dsa/dsa_ameth2016-03-03
OSV
openssl vulnerabilities2016-03-01

📋Vendor Advisories

10
Palo Alto
PAN-SA-2024-0014 Informational Bulletin: Impact of OSS CVEs in Cortex XDR Agent2024-11-07
CISA ICS
Siemens SCALANCE X-200RNA Switch Devices2022-12-19
Apple
CVE-2016-0705: Xcode 8.12016-10-27
Android
CVE-2016-0705: Android Security Bulletin 2016-05-01 CVE: CVE-2016-0705 Severity: MEDIUM Affected AOSP versions: 42016-05-01
BSD
FreeBSD-SA-16:12.openssl: Multiple OpenSSL vulnerabilities2016-03-10

🕵️Threat Intelligence

3
Qualys
Oracle Critical Patch Update April 2016 | Qualys2016-04-22
Qualys
Oracle Critical Patch Update April 2016 | Qualys2016-04-22
Tenable
[R12] OpenSSL &#039;20160301&#039; Advisory Affects Tenable Products2016-03-02

📄Research Papers

1
arXiv
A Novel Model for Vulnerability Analysis through Enhanced Directed Graphs and Quantitative Metrics2021-12-13

💬Community

4
Bugzilla
CVE-2016-0705 OpenSSL: Double-free in DSA code [fedora-all]2016-02-29
Bugzilla
CVE-2016-0705 openssl101e: OpenSSL: Double-free in DSA code [epel-5]2016-02-29
Bugzilla
CVE-2016-0705 mingw-openssl: OpenSSL: Double-free in DSA code [fedora-all]2016-02-29
Bugzilla
CVE-2016-0705 OpenSSL: Double-free in DSA code2016-02-22
CVE-2016-0705 — Debian Openssl vulnerability | cvebase