CVE-2016-2109
published 2016-05-05CVE-2016-2109: The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in the ASN.1 BIO implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote…
PriorityP345high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
29.21%
98.0th percentile
The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in the ASN.1 BIO implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (memory consumption) via a short invalid encoding.
Affected
32 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | os_x_el_capitan_v10.11.6_and_security_update_2016-004 | — | — |
| debian | openssl | < openssl 1.0.2h-1 (bookworm) | openssl 1.0.2h-1 (bookworm) |
| android | — | — | |
| openssl | openssl | <= 1.0.1s | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | >= 0 < 1.0.2h-1 | 1.0.2h-1 |
| openssl | openssl | >= 0 < 1.0.2h-1 | 1.0.2h-1 |
| openssl | openssl | >= 0 < 1.0.2h-1 | 1.0.2h-1 |
| openssl | openssl | >= 0 < 1.0.2h-1 | 1.0.2h-1 |
| openssl | openssl | >= 0 < 1.0.1f-1ubuntu2.19 | 1.0.1f-1ubuntu2.19 |
| openssl | openssl | >= 0 < 1.0.2g-1ubuntu4.1 | 1.0.2g-1ubuntu4.1 |
| paloalto | cortex_xdr | — | — |
| paloalto | globalprotect | — | — |
| paloalto | pan-os | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_hpc_node | — | — |
| redhat | enterprise_linux_hpc_node | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerable function is asn1_d2i_read_bio in crypto/asn1/a_d2i_fp.c; monitor for excessive memory allocation triggered by short invalid ASN.1 BIO encodings passed to d2i BIO functions such as d2i_CMS_bio() ↗
- →Applications parsing untrusted data through d2i BIO functions are the attack surface; TLS applications are explicitly noted as NOT affected — focus detection on non-TLS applications accepting untrusted ASN.1 BIO input ↗
- →Alert on processes showing abnormal heap/memory growth consistent with memory exhaustion when processing ASN.1-encoded data from BIO inputs ↗
- ·Only OpenSSL versions before 1.0.1t and 1.0.2 before 1.0.2h are vulnerable; patched versions are 1.0.1t and 1.0.2h respectively ↗
- ·TLS applications using OpenSSL are explicitly NOT affected by this CVE; only non-TLS applications that accept untrusted ASN.1 BIO input are at risk ↗
- ·FreeBSD systems on EBCDIC are not affected by CVE-2016-2176 (a related but distinct CVE); FreeBSD does not run on EBCDIC systems ↗
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2024-0014 Informational Bulletin: Impact of OSS CVEs in Cortex XDR Agent
vendor_paloalto·2024-11-07·CVSS 6.8
CVE-2014-0195 [MEDIUM] PAN-SA-2024-0014 Informational Bulletin: Impact of OSS CVEs in Cortex XDR Agent
PAN-SA-2024-0014 Informational Bulletin: Impact of OSS CVEs in Cortex XDR Agent
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to Cortex XDR Agent. While Cortex XDR Agent may include the
CVEs: CVE-2014-0195, CVE-2014-0224, CVE-2014-3509, CVE-2014-3512, CVE-2014-3513, CVE-2014-3567, CVE-2015-0209, CVE-2015-0292, CVE-2015-1789, CVE-2015-1791, CVE-2015-1793, CVE-2015-3194, CVE-2016-0705, CVE-2016-0797, CVE-2016-0798, CVE-2016-0799, CVE-2016-2105, CVE-2016-2106, CVE-2016-2108, CVE-2016-2109, CVE-2016-2176, CVE-2016-2177, CVE-2016-2179, CVE-2016-2180, CVE-2016-2181, CVE-2016-2182, CVE-2016-2183, CVE-2016-6302, CVE-2016-6303, CVE-2016-6304, CVE-2019-1551, CVE-2019-1552, CVE-2019-1559, CVE-2019-1563, CVE-2020-196
CISA ICS
Siemens SCALANCE X-200RNA Switch Devices
cisa_ics·2022-12-19
Siemens SCALANCE X-200RNA Switch Devices
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SCALANCE X-200RNA Switch Devices
Last RevisedDecember 19, 2022
Alert CodeICSA-22-349-21
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity/public exploits are available
- Vendor: Siemens
- Equipment: SCALANCE X-200RNA switch devices before V3.2.7
- Vulnerabilities: Observable Timing Discrepancy; Race Condition; Improper Restriction of Operations within the Bounds of a Memory Buffer; Improper Input Validation; NULL Pointer Dereference; Use After Free; Cryptographic Issues; Comparison of Incompatible Types; Resource Management
Android
CVE-2016-2109: Android Security Bulletin 2017-07-01
CVE: CVE-2016-2109
Severity: HIGH
Type: DoS
Affected AOSP versions: 4
vendor_android·2017-07-01·CVSS 7.5
CVE-2016-2109 [HIGH] CVE-2016-2109: Android Security Bulletin 2017-07-01
CVE: CVE-2016-2109
Severity: HIGH
Type: DoS
Affected AOSP versions: 4
Android Security Bulletin 2017-07-01
CVE: CVE-2016-2109
Severity: HIGH
Type: DoS
Affected AOSP versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2
References: A-35443725
Palo Alto
PAN-SA-2016-0023 OpenSSL Vulnerabilities
vendor_paloalto·2016-09-02·CVSS 2.6
CVE-2013-0169 [LOW] CWE-119 PAN-SA-2016-0023 OpenSSL Vulnerabilities
PAN-SA-2016-0023 OpenSSL Vulnerabilities
The OpenSSL library embedded in the GlobalProtect™ agent, TerminalServer™ agent and UserID™ agent is
CVEs: CVE-2013-0169, CVE-2016-2105, CVE-2016-2106, CVE-2016-2107, CVE-2016-2109, CVE-2016-2176
Affected products: GlobalProtect
Palo Alto
PAN-SA-2016-0020 OpenSSL Vulnerabilities
vendor_paloalto·2016-08-15·CVSS 7.5
CVE-2014-8176 [HIGH] CWE-119 PAN-SA-2016-0020 OpenSSL Vulnerabilities
PAN-SA-2016-0020 OpenSSL Vulnerabilities
The OpenSSL library has been found to contain several vulnerabilities CVE-2014-8176, CVE-2015-1788, CVE-2015-1789, CVE-2015-1790, CVE-2015-1791, CVE-2015-1792, CVE-2015-1794, CVE-2015-3195, CVE-2015-4000, CVE-2016-2105, CVE-2016-2106, CVE-2016-2107, CVE-2016-2108, CVE-2016-2109, CVE-2016-2176, CVE-2016-2842. Palo Alto Networks software makes use of the vulnerable library. (Ref # 95622). The OpenSSL library in use by PAN-OS is patched on a regular basis. Severities of the CVEs listed under the summary section range from low to high but, have not been shown to be exploitable at the time of this advisory. This issue affects PAN-OS 5.0.X; PAN-OS-5.1.X; PAN-OS 6.0.13 and earlier; PAN-OS 6.1.12 and earlier; PAN-OS 7.0.8 and earlier; PAN-OS 7.1.3 and earl
Apple
CVE-2016-2109: OS X El Capitan v10.11.6 and Security Update 2016-004
vendor_apple·2016-07-18·CVSS 7.5
CVE-2016-2109 [HIGH] CVE-2016-2109: OS X El Capitan v10.11.6 and Security Update 2016-004
Apple Security Update: About the security content of OS X El Capitan v10.11.6 and Security Update 2016-004
Product: OS X El Capitan v10.11.6 and Security Update 2016-004
CVE: CVE-2016-2109
Component: LibreSSL
Impact: A remote attacker may be able to execute arbitrary code
Description: Multiple issues existed in LibreSSL before 2.2.7. These were addressed by updating LibreSSL to version 2.2.7.
BSD
FreeBSD-SA-16:17.openssl: Multiple OpenSSL vulnerabilities
bsd_advisories·2016-05-04·CVSS 7.5
CVE-2016-2105 [HIGH] FreeBSD-SA-16:17.openssl: Multiple OpenSSL vulnerabilities
FreeBSD-SA-16:17.openssl Security Advisory
The FreeBSD Project
Topic: Multiple OpenSSL vulnerabilities
Category: contrib
Module: openssl
Announced: 2016-05-04
Credits: OpenSSL Project
Affects: All supported versions of FreeBSD.
Corrected: 2016-05-03 18:54:20 UTC (stable/10, 10.3-STABLE)
2016-05-04 15:25:47 UTC (releng/10.3, 10.3-RELEASE-p2)
2016-05-04 15:26:23 UTC (releng/10.2, 10.2-RELEASE-p16)
2016-05-04 15:27:09 UTC (releng/10.1, 10.1-RELEASE-p33)
2016-05-04 06:53:02 UTC (stable/9, 9.3-STABLE)
2016-05-04 15:27:09 UTC (releng/9.3, 9.3-RELEASE-p41)
CVE Name: CVE-2016-2105, CVE-2016-2106, CVE-2016-2107, CVE-2016-2109,
CVE-2016-2176
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, ple
Cisco
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: May 2016
vendor_cisco·2016-05-04
CVE-2016-2105 [MEDIUM] CWE-119 Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: May 2016
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: May 2016
On May 3, 2016, the OpenSSL Software Foundation released a security advisory that included six vulnerabilities. Of the six vulnerabilities disclosed, four of them may cause memory corruption or excessive memory usage, one could allow a padding oracle attack to decrypt traffic when the connection uses an AES CBC cipher and the server supports AES-NI, and, lastly, one is specific to a product performing an operation with Extended Binary Coded Decimal Interchange Code (EBCDIC) encoding.
Multiple Cisco products incorporate a version of the OpenSSL package affected by one or more vulnerabilities.
This advisory will be updated as additional information becomes available.
This advisory is available at the following link:
Ubuntu
OpenSSL vulnerabilities
vendor_ubuntu·2016-05-03·CVSS 7.5
CVE-2016-2105 [HIGH] OpenSSL vulnerabilities
Title: OpenSSL vulnerabilities
Summary: Several security issues were fixed in OpenSSL.
Huzaifa Sidhpurwala, Hanno Böck, and David Benjamin discovered that OpenSSL
incorrectly handled memory when decoding ASN.1 structures. A remote
attacker could use this issue to cause OpenSSL to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2016-2108)
Juraj Somorovsky discovered that OpenSSL incorrectly performed padding when
the connection uses the AES CBC cipher and the server supports AES-NI. A
remote attacker could possibly use this issue to perform a padding oracle
attack and decrypt traffic. (CVE-2016-2107)
Guido Vranken discovered that OpenSSL incorrectly handled large amounts of
input data to the EVP_EncodeUpdate() function. A remote attacker could use
this
Red Hat
openssl: ASN.1 BIO handling of large amounts of data
vendor_redhat·2016-04-23·CVSS 7.5
CVE-2016-2109 [HIGH] CWE-20 openssl: ASN.1 BIO handling of large amounts of data
openssl: ASN.1 BIO handling of large amounts of data
The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in the ASN.1 BIO implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (memory consumption) via a short invalid encoding.
A denial of service flaw was found in the way OpenSSL parsed certain ASN.1-encoded data from BIO (OpenSSL's I/O abstraction) inputs. An application using OpenSSL that accepts untrusted ASN.1 BIO input could be forced to allocate an excessive amount of data.
Package: openssl (Red Hat Enterprise Linux 4) - Will not fix
Package: openssl096b (Red Hat Enterprise Linux 4) - Will not fix
Package: openssl (Red Hat Enterprise Linux 5) - Will not fix
Package: openssl097a (Red Hat Enterprise Linux 5) - Wi
Debian
CVE-2016-2109: openssl - The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in the ASN.1 BIO implem...
vendor_debian·2016·CVSS 7.5
CVE-2016-2109 [HIGH] CVE-2016-2109: openssl - The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in the ASN.1 BIO implem...
The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in the ASN.1 BIO implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (memory consumption) via a short invalid encoding.
Scope: local
bookworm: resolved (fixed in 1.0.2h-1)
bullseye: resolved (fixed in 1.0.2h-1)
forky: resolved (fixed in 1.0.2h-1)
sid: resolved (fixed in 1.0.2h-1)
trixie: resolved (fixed in 1.0.2h-1)
Cisco
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: May 2016
vendor_cisco
CVE-2016-2109 Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: May 2016
CVE-2016-2109: Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: May 2016
On May 3, 2016, the OpenSSL Software Foundation released a security advisory that included six vulnerabilities. Of the six vulnerabilities disclosed, four of them may cause memory corruption or excessive memory usage, one could allow a padding oracle attack to decrypt traffic when the connection uses an AES CBC cipher and the server supports AES-NI, and, lastly, one is specific to a product performing an operation with Extended Binary Coded Decimal Interchange Code (EBCDIC) encoding. Multiple Cisco products incorporate a version of the OpenSSL package affected by one or more vulnerabilities. This advisory will be updated as additional information becomes available. This advisory is available at the follow
GHSA
GHSA-mq63-fmfx-8qc3: The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp
ghsa_unreviewed·2022-05-14
CVE-2016-2109 [HIGH] GHSA-mq63-fmfx-8qc3: The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp
The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in the ASN.1 BIO implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (memory consumption) via a short invalid encoding.
OSV
CVE-2016-2109: The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp
osv·2016-05-05·CVSS 7.5
CVE-2016-2109 [HIGH] CVE-2016-2109: The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp
The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in the ASN.1 BIO implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (memory consumption) via a short invalid encoding.
OSV
openssl vulnerabilities
osv·2016-05-03·CVSS 7.5
CVE-2016-2108 [HIGH] openssl vulnerabilities
openssl vulnerabilities
Huzaifa Sidhpurwala, Hanno Böck, and David Benjamin discovered that OpenSSL
incorrectly handled memory when decoding ASN.1 structures. A remote
attacker could use this issue to cause OpenSSL to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2016-2108)
Juraj Somorovsky discovered that OpenSSL incorrectly performed padding when
the connection uses the AES CBC cipher and the server supports AES-NI. A
remote attacker could possibly use this issue to perform a padding oracle
attack and decrypt traffic. (CVE-2016-2107)
Guido Vranken discovered that OpenSSL incorrectly handled large amounts of
input data to the EVP_EncodeUpdate() function. A remote attacker could use
this issue to cause OpenSSL to crash, resulting in a denial of servic
No detection rules found.
No public exploits indexed.
HackerOne
ASN.1 BIO excessive memory allocation (CVE-2016-2109)
hackerone·2016-05-03·CVSS 7.5
CVE-2016-2109 [HIGH] ASN.1 BIO excessive memory allocation (CVE-2016-2109)
ASN.1 BIO excessive memory allocation (CVE-2016-2109)
On 4 April 2016 I reported a bug to the OpenSSL Security Team where I was able to force OpenSSL to use large amounts of cpu time, memory and swap space. They confirmed receipt on 6 April 2016 and on 22 April 2016 I was notified that they were assigning CVE-2016-2109 to this flaw and the fix was committed to git on 22 April 2016.
```
The main cause is the way asn1_d2i_read_bio works: it allocates memory depending on the length field. Your test cases looks like this:
30 84 30 30 30 30 30
Which translates to a SEQUENCE with a length of 0x30303030 which explains the huge memory requirements.
In some cases this is intended (for example large CMS messages) so we can't just reject these. Additionally because the input comes from a BIO we
Bugzilla
CVE-2016-2109 mingw-openssl: openssl: ASN.1 BIO handling of large amounts of data [fedora-all]
bugzilla·2016-04-25·CVSS 7.5
CVE-2016-2109 [HIGH] CVE-2016-2109 mingw-openssl: openssl: ASN.1 BIO handling of large amounts of data [fedora-all]
CVE-2016-2109 mingw-openssl: openssl: ASN.1 BIO handling of large amounts of data [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple suppo
Bugzilla
CVE-2016-2109 openssl101e: openssl: ASN.1 BIO handling of large amounts of data [epel-5]
bugzilla·2016-04-25·CVSS 7.5
CVE-2016-2109 [HIGH] CVE-2016-2109 openssl101e: openssl: ASN.1 BIO handling of large amounts of data [epel-5]
CVE-2016-2109 openssl101e: openssl: ASN.1 BIO handling of large amounts of data [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
[bug automatically created by: add-track
Bugzilla
CVE-2016-2109 openssl: ASN.1 BIO handling of large amounts of data [fedora-all]
bugzilla·2016-04-25·CVSS 7.5
CVE-2016-2109 [HIGH] CVE-2016-2109 openssl: ASN.1 BIO handling of large amounts of data [fedora-all]
CVE-2016-2109 openssl: ASN.1 BIO handling of large amounts of data [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions o
Bugzilla
CVE-2016-2109 openssl: ASN.1 BIO handling of large amounts of data
bugzilla·2016-04-25·CVSS 7.5
CVE-2016-2109 [HIGH] CVE-2016-2109 openssl: ASN.1 BIO handling of large amounts of data
CVE-2016-2109 openssl: ASN.1 BIO handling of large amounts of data
An input validation flaw was found in the way OpenSSL parsed certain ASN.1-encoded data from BIO (OpenSSL's I/O abstraction) inputs. An application using OpenSSL that accepts untrusted ASN.1 BIO input could be forced to allocate an excessive amount of data, potentially resulting in a denial of service.
Upstream commit:
https://git.openssl.org/?p=openssl.git;a=commitdiff;h=c62981390d6cf9e3d612c489b8b77c2913b25807
Discussion:
Created openssl101e tracking bugs for this issue:
Affects: epel-5 [bug 1330105]
---
Created openssl tracking bugs for this issue:
Affects: fedora-all [bug 1330103]
---
Created mingw-openssl tracking bugs for this issue:
Affects: fedora-all [bug 1330104]
---
Upstream test case:
https://git.
Tenable
[R5] OpenSSL '20160503' Advisory Affects Tenable Products
blogs_tenable·2016-05-18
[R5] OpenSSL '20160503' Advisory Affects Tenable Products
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10759http://lists.apple.com/archives/security-announce/2016/Jul/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00016.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00019.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00029.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00030.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00036.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00055.htmlhttp://packetstormsecurity.com/files/136912/Slackware-Security-Advisory-openssl-Updates.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0722.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0996.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2056.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2073.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2957.htmlhttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160504-opensslhttp://www.debian.org/security/2016/dsa-3566http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/87940http://www.securityfocus.com/bid/91787http://www.securitytracker.com/id/1035721http://www.slackware.com/security/viewer.php?l=slackware-security&y=2016&m=slackware-security.542103http://www.ubuntu.com/usn/USN-2959-1https://bto.bluecoat.com/security-advisory/sa123https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdfhttps://git.openssl.org/?p=openssl.git%3Ba=commit%3Bh=c62981390d6cf9e3d612c489b8b77c2913b25807https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03756en_ushttps://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03765en_ushttps://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05320149https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA40202https://kc.mcafee.com/corporate/index?page=content&id=SB10160https://security.gentoo.org/glsa/201612-16https://security.netapp.com/advisory/ntap-20160504-0001/https://source.android.com/security/bulletin/2017-07-01https://support.apple.com/HT206903https://www.freebsd.org/security/advisories/FreeBSD-SA-16:17.openssl.aschttps://www.openssl.org/news/secadv/20160503.txthttps://www.tenable.com/security/tns-2016-18http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10759http://lists.apple.com/archives/security-announce/2016/Jul/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00016.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00019.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00029.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00030.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00036.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00055.htmlhttp://packetstormsecurity.com/files/136912/Slackware-Security-Advisory-openssl-Updates.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0722.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0996.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2056.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2073.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2957.htmlhttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160504-opensslhttp://www.debian.org/security/2016/dsa-3566http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/87940http://www.securityfocus.com/bid/91787http://www.securitytracker.com/id/1035721http://www.slackware.com/security/viewer.php?l=slackware-security&y=2016&m=slackware-security.542103http://www.ubuntu.com/usn/USN-2959-1https://bto.bluecoat.com/security-advisory/sa123https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdfhttps://git.openssl.org/?p=openssl.git%3Ba=commit%3Bh=c62981390d6cf9e3d612c489b8b77c2913b25807https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03756en_ushttps://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03765en_ushttps://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05320149
+ 10 more references
2016-05-05
Published