Severity
7.5HIGHNVD
EPSS
4.2%
top 11.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 1
Latest updateMay 13

Description

The TS_OBJ_print_bio function in crypto/ts/ts_lib.c in the X.509 Public Key Infrastructure Time-Stamp Protocol (TSP) implementation in OpenSSL through 1.0.2h allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted time-stamp file that is mishandled by the "openssl ts" command.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

Debianopenssl/openssl< 1.0.2i-1+3
NVDopenssl/openssl30 versions+29
NVDoracle/linux6, 7+1

Patches

🔴Vulnerability Details

3
GHSA
GHSA-9mvv-53wm-cpqm: The TS_OBJ_print_bio function in crypto/ts/ts_lib2022-05-13
OSV
CVE-2016-2180: The TS_OBJ_print_bio function in crypto/ts/ts_lib2016-08-01
CVEList
CVE-2016-2180: The TS_OBJ_print_bio function in crypto/ts/ts_lib2016-08-01

📋Vendor Advisories

5
Cisco
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 20162016-09-27
BSD
FreeBSD-SA-16:26.openssl: Multiple OpenSSL vulnerabilities2016-09-23
Ubuntu
OpenSSL vulnerabilities2016-09-22
Red Hat
OpenSSL: OOB read in TS_OBJ_print_bio()2016-07-21
Debian
CVE-2016-2180: openssl - The TS_OBJ_print_bio function in crypto/ts/ts_lib.c in the X.509 Public Key Infr...2016

💬Community

5
HackerOne
OOB read in TS_OBJ_print_bio() (CVE-2016-2180)2017-05-25
Bugzilla
CVE-2016-2180 openssl101e: OpenSSL: OOB read in TS_OBJ_print_bio() [epel-5]2016-07-25
Bugzilla
CVE-2016-2180 OpenSSL: OOB read in TS_OBJ_print_bio()2016-07-25
Bugzilla
CVE-2016-2180 OpenSSL: OOB read in TS_OBJ_print_bio() [fedora-all]2016-07-25
Bugzilla
CVE-2016-2180 mingw-openssl: OpenSSL: OOB read in TS_OBJ_print_bio() [fedora-all]2016-07-25
CVE-2016-2180 — Out-of-bounds Read in Openssl | cvebase