cbcvebase.
CVE-2016-2108
published 2016-05-05

CVE-2016-2108: The ASN.1 implementation in OpenSSL before 1.0.1o and 1.0.2 before 1.0.2c allows remote attackers to execute arbitrary code or cause a denial of service…

PriorityP267critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
77.91%
99.5th percentile
The ASN.1 implementation in OpenSSL before 1.0.1o and 1.0.2 before 1.0.2c allows remote attackers to execute arbitrary code or cause a denial of service (buffer underflow and memory corruption) via an ANY field in crafted serialized data, aka the "negative zero" issue.

Affected

48 ranges· showing 25
VendorProductVersion rangeFixed in
appleos_x_el_capitan_v10.11.6_and_security_update_2016-004
debianopenssl< openssl 1.0.2c-1 (bookworm)openssl 1.0.2c-1 (bookworm)
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid

Detection & IOCsextracted from sources · hover to see the quote

  • Attack vector is a crafted serialized ASN.1 data structure containing an ANY field with a 'negative zero' value, delivered via a specially crafted certificate to trigger buffer underflow and memory corruption in OpenSSL's ASN.1 encoder/decoder.
  • Attack surface includes certificate verification and re-encoding paths in OpenSSL; monitor for crashes or unexpected code execution in applications compiled against OpenSSL during certificate processing.
  • Cisco products are affected; Cisco Bug IDs CSCuz52348, CSCuz52349, CSCuz52351 can be used to track and correlate affected Cisco product versions in asset inventories.
  • Android devices running AOSP versions 4.4.4, 5.0.2, 5.1.1, 6.0, and 6.0.1 are critically affected; use Android reference A-28175332 for patch tracking.
  • ·Vulnerable OpenSSL version range is 'before 1.0.1o' and '1.0.2 before 1.0.2c'; ensure asset inventory checks for these specific version boundaries, as 1.0.1o and 1.0.2c are the fixed versions.
  • ·Apple's LibreSSL (a fork of OpenSSL) is also affected; the fix was addressed by updating LibreSSL to version 2.2.7 in OS X El Capitan v10.11.6.
  • ·Several Red Hat OpenSSL packages (openssl096b, openssl097a, openssl098e) are marked 'Will not fix', meaning vulnerable versions may persist in RHEL 4–7 environments and should be flagged in detection/asset management.
  • ·Cisco advisory covers six OpenSSL vulnerabilities simultaneously (May 3, 2016 advisory); CVE-2016-2108 is one of four memory corruption issues — ensure Cisco product triage distinguishes between the individual CVEs when applying fixes.

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.