CVE-2016-2180 — Out-of-bounds Read in Openssl
Severity
7.5HIGHNVD
EPSS
4.2%
top 11.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 1
Latest updateMay 13
Description
The TS_OBJ_print_bio function in crypto/ts/ts_lib.c in the X.509 Public Key Infrastructure Time-Stamp Protocol (TSP) implementation in OpenSSL through 1.0.2h allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted time-stamp file that is mishandled by the "openssl ts" command.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6
Affected Packages3 packages
Patches
🔴Vulnerability Details
3📋Vendor Advisories
5Debian▶
CVE-2016-2180: openssl - The TS_OBJ_print_bio function in crypto/ts/ts_lib.c in the X.509 Public Key Infr...↗2016
💬Community
5Bugzilla
▶