Severity
9.8CRITICAL
EPSS
37.0%
top 2.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 5
Latest updateMay 14

Description

The ASN.1 implementation in OpenSSL before 1.0.1o and 1.0.2 before 1.0.2c allows remote attackers to execute arbitrary code or cause a denial of service (buffer underflow and memory corruption) via an ANY field in crafted serialized data, aka the "negative zero" issue.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages8 packages

Debianopenssl< 1.0.2c-1+3
Ubuntuopenssl< 1.0.1f-1ubuntu2.19+1
NVDopenssl/openssl1.0.1n+3
NVDgoogle/android22 versions+21

Also affects: Enterprise Linux 7.2

🔴Vulnerability Details

4
GHSA
GHSA-cf8v-cq93-65gh: The ASN2022-05-14
CVEList
CVE-2016-2108: The ASN2016-05-05
OSV
CVE-2016-2108: The ASN2016-05-05
OSV
openssl vulnerabilities2016-05-03

📋Vendor Advisories

6
Apple
CVE-2016-2108: OS X El Capitan v10.11.6 and Security Update 2016-0042016-07-18
Android
CVE-2016-2108: Android Security Bulletin 2016-07-01 CVE: CVE-2016-2108 Severity: CRITICAL Affected AOSP versions: 42016-07-01
Cisco
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: May 20162016-05-04
Red Hat
openssl: Memory corruption in the ASN.1 encoder2016-05-03
Ubuntu
OpenSSL vulnerabilities2016-05-03

💬Community

5
Bugzilla
CVE-2016-2105 CVE-2016-2106 CVE-2016-2107 CVE-2016-2108 mingw-openssl: various flaws [epel-7]2016-05-03
Bugzilla
CVE-2016-2105 CVE-2016-2106 CVE-2016-2107 CVE-2016-2108 openssl: various flaws [fedora-all]2016-05-03
Bugzilla
CVE-2016-2105 CVE-2016-2106 CVE-2016-2107 CVE-2016-2108 mingw-openssl: various flaws [fedora-all]2016-05-03
Bugzilla
CVE-2016-2105 CVE-2016-2106 CVE-2016-2107 CVE-2016-2108 openssl101e: various flaws [epel-5]2016-05-03
Bugzilla
CVE-2016-2108 openssl: Memory corruption in the ASN.1 encoder2016-04-28
CVE-2016-2108 (CRITICAL CVSS 9.8) | The ASN.1 implementation in OpenSSL | cvebase.io