Severity
9.8CRITICAL
EPSS
29.1%
top 3.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 20
Latest updateMay 13

Description

OpenSSL through 1.0.2h incorrectly uses pointer arithmetic for heap-buffer boundary checks, which might allow remote attackers to cause a denial of service (integer overflow and application crash) or possibly have unspecified other impact by leveraging unexpected malloc behavior, related to s3_srvr.c, ssl_sess.c, and t1_lib.c.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages8 packages

Debianopenssl< 1.0.2i-1+3
Ubuntuopenssl< 1.0.1f-1ubuntu2.22+1
NVDopenssl/openssl30 versions+29
NVDoracle/linux5, 6, 7+2
NVDhp/icewall_sso10.0

Patches

🔴Vulnerability Details

6
GHSA
GHSA-pgwh-48cm-wrqw: OpenSSL through 12022-05-13
OSV
openssl vulnerabilities2017-01-31
OSV
openssl regression2016-09-23
OSV
openssl vulnerabilities2016-09-22
CVEList
CVE-2016-2177: OpenSSL through 12016-06-20

📋Vendor Advisories

6
Ubuntu
OpenSSL vulnerabilities2017-01-31
Cisco
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 20162016-09-27
BSD
FreeBSD-SA-16:26.openssl: Multiple OpenSSL vulnerabilities2016-09-23
Ubuntu
OpenSSL vulnerabilities2016-09-22
Red Hat
openssl: Possible integer overflow vulnerabilities in codebase2016-05-05

💬Community

5
HackerOne
CVE-2016-2177 Undefined pointer arithmetic in SSL code2016-09-20
Bugzilla
CVE-2016-2177 openssl: Possible integer overflow vulnerabilities in codebase2016-06-01
Bugzilla
CVE-2016-2177 openssl101e: openssl: Possible integer overflow vulnerabilities in codebase [epel-5]2016-06-01
Bugzilla
CVE-2016-2177 mingw-openssl: openssl: Possible integer overflow vulnerabilities in codebase [fedora-all]2016-06-01
Bugzilla
CVE-2016-2177 openssl: Possible integer overflow vulnerabilities in codebase [fedora-all]2016-06-01
CVE-2016-2177 (CRITICAL CVSS 9.8) | OpenSSL through 1.0.2h incorrectly | cvebase.io