Severity
9.8CRITICAL
EPSS
29.2%
top 3.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 16
Latest updateMay 13

Description

The BN_bn2dec function in crypto/bn/bn_print.c in OpenSSL before 1.1.0 does not properly validate division results, which allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or possibly have unspecified other impact via unknown vectors.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages8 packages

Debianopenssl< 1.0.2i-1+3
Ubuntuopenssl< 1.0.1f-1ubuntu2.21+1
NVDopenssl/openssl30 versions+29
NVDoracle/linux5, 6, 7+2
NVDhp/icewall_sso10.0

🔴Vulnerability Details

4
GHSA
GHSA-qc4g-43pw-wqh8: The BN_bn2dec function in crypto/bn/bn_print2022-05-13
OSV
openssl regression2016-09-23
OSV
CVE-2016-2182: The BN_bn2dec function in crypto/bn/bn_print2016-09-16
CVEList
CVE-2016-2182: The BN_bn2dec function in crypto/bn/bn_print2016-09-16

📋Vendor Advisories

7
Android
CVE-2016-2182: Android Security Bulletin 2017-03-01 CVE: CVE-2016-2182 Severity: CRITICAL Affected AOSP versions: 42017-03-01
Cisco
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 20162016-09-27
Ubuntu
OpenSSL regression2016-09-23
BSD
FreeBSD-SA-16:26.openssl: Multiple OpenSSL vulnerabilities2016-09-23
Ubuntu
OpenSSL vulnerabilities2016-09-22

💬Community

5
HackerOne
OOB write in BN_bn2dec() (CVE-2016-2182)2017-05-25
Bugzilla
CVE-2016-2182 openssl101e: openssl: Out-of-bounds write caused by unchecked errors in BN_bn2dec() [epel-5]2016-08-16
Bugzilla
CVE-2016-2182 openssl: Out-of-bounds write caused by unchecked errors in BN_bn2dec()2016-08-16
Bugzilla
CVE-2016-2182 openssl: Out-of-bounds write caused by unchecked errors in BN_bn2dec() [fedora-all]2016-08-16
Bugzilla
CVE-2016-2182 mingw-openssl: openssl: Out-of-bounds write caused by unchecked errors in BN_bn2dec() [fedora-all]2016-08-16
CVE-2016-2182 (CRITICAL CVSS 9.8) | The BN_bn2dec function in crypto/bn | cvebase.io