CVE-2016-2109
Severity
7.5HIGH
EPSS
57.9%
top 1.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 5
Latest updateMay 14
Description
The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in the ASN.1 BIO implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (memory consumption) via a short invalid encoding.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6
Affected Packages6 packages
Also affects: Enterprise Linux 7.2
🔴Vulnerability Details
3📋Vendor Advisories
7Android▶
CVE-2016-2109: Android Security Bulletin 2017-07-01
CVE: CVE-2016-2109
Severity: HIGH
Type: DoS
Affected AOSP versions: 4↗2017-07-01
💬Community
5Bugzilla▶
CVE-2016-2109 mingw-openssl: openssl: ASN.1 BIO handling of large amounts of data [fedora-all]↗2016-04-25
Bugzilla
▶