CVE-2016-0798Improper Restriction of Operations within the Bounds of a Memory Buffer in Openssl

Severity
7.5HIGHNVD
OSV5.1
EPSS
26.0%
top 3.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 3
Latest updateNov 7

Description

Memory leak in the SRP_VBASE_get_by_user implementation in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g allows remote attackers to cause a denial of service (memory consumption) by providing an invalid username in a connection attempt, related to apps/s_server.c and crypto/srp/srp_vfy.c.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages5 packages

debiandebian/openssl< openssl 1.0.2g-1 (bookworm)
Debianopenssl/openssl< 1.0.2g-1+3
Ubuntuopenssl/openssl< 1.0.1f-1ubuntu2.18
NVDopenssl/openssl26 versions+25

🔴Vulnerability Details

3
GHSA
GHSA-8wvj-cwfq-pc44: Memory leak in the SRP_VBASE_get_by_user implementation in OpenSSL 12022-05-17
OSV
CVE-2016-0798: Memory leak in the SRP_VBASE_get_by_user implementation in OpenSSL 12016-03-03
OSV
openssl vulnerabilities2016-03-01

📋Vendor Advisories

8
Palo Alto
PAN-SA-2024-0014 Informational Bulletin: Impact of OSS CVEs in Cortex XDR Agent2024-11-07
CISA ICS
Siemens SCALANCE X-200RNA Switch Devices2022-12-19
BSD
FreeBSD-SA-16:12.openssl: Multiple OpenSSL vulnerabilities2016-03-10
Cisco
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: March 20162016-03-02
Ubuntu
OpenSSL vulnerabilities2016-03-01

🕵️Threat Intelligence

1
Tenable
[R12] OpenSSL &#039;20160301&#039; Advisory Affects Tenable Products2016-03-02

💬Community

1
Bugzilla
CVE-2016-0798 OpenSSL: Avoid memory leak in SRP2016-02-25
CVE-2016-0798 — Debian Openssl vulnerability | cvebase