CVE-2016-2182
Severity
9.8CRITICAL
EPSS
29.2%
top 3.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 16
Latest updateMay 13
Description
The BN_bn2dec function in crypto/bn/bn_print.c in OpenSSL before 1.1.0 does not properly validate division results, which allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or possibly have unspecified other impact via unknown vectors.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9
Affected Packages8 packages
🔴Vulnerability Details
4📋Vendor Advisories
7Android▶
CVE-2016-2182: Android Security Bulletin 2017-03-01
CVE: CVE-2016-2182
Severity: CRITICAL
Affected AOSP versions: 4↗2017-03-01
💬Community
5Bugzilla▶
CVE-2016-2182 openssl101e: openssl: Out-of-bounds write caused by unchecked errors in BN_bn2dec() [epel-5]↗2016-08-16
Bugzilla
▶
Bugzilla▶
CVE-2016-2182 openssl: Out-of-bounds write caused by unchecked errors in BN_bn2dec() [fedora-all]↗2016-08-16
Bugzilla▶
CVE-2016-2182 mingw-openssl: openssl: Out-of-bounds write caused by unchecked errors in BN_bn2dec() [fedora-all]↗2016-08-16