cbcvebase.
CVE-2016-6304
published 2016-09-26

CVE-2016-6304: Multiple memory leaks in t1_lib.c in OpenSSL before 1.0.1u, 1.0.2 before 1.0.2i, and 1.1.0 before 1.1.0a allow remote attackers to cause a denial of service…

PriorityP352high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
63.03%
99.1th percentile
Multiple memory leaks in t1_lib.c in OpenSSL before 1.0.1u, 1.0.2 before 1.0.2i, and 1.1.0 before 1.1.0a allow remote attackers to cause a denial of service (memory consumption) via large OCSP Status Request extensions.

Affected

46 ranges· showing 25
VendorProductVersion rangeFixed in
applemacos_sierra_10.12.2_security_update_2016-003_el_capitan_and_security_update_201
debianopenssl< openssl 1.0.2i-1 (bookworm)openssl 1.0.2i-1 (bookworm)
nodejsnode.js>= 0.10.0 < 0.10.470.10.47
nodejsnode.js>= 0.12.0 < 0.12.160.12.16
nodejsnode.js>= 4.0.0 < 4.6.04.6.0
nodejsnode.js>= 6.0.0 < 6.7.06.7.0
novellsuse_linux_enterprise_module_for_web_scripting
opensslopenssl
opensslopenssl
opensslopenssl
opensslopenssl
opensslopenssl
opensslopenssl
opensslopenssl
opensslopenssl
opensslopenssl
opensslopenssl
opensslopenssl
opensslopenssl
opensslopenssl
opensslopenssl
opensslopenssl
opensslopenssl
opensslopenssl
opensslopenssl

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability is triggered via large OCSP Status Request extensions sent during TLS session renegotiation, causing unbounded memory growth in t1_lib.c
  • Attack vector is TLS session renegotiation with oversized OCSP Status Request extension data; monitor for repeated TLS renegotiation attempts with abnormally large status_request extensions
  • Only TLS servers with OCSP stapling explicitly enabled are affected; detection should focus on servers running vulnerable OpenSSL versions (before 1.0.1u, before 1.0.2i, before 1.1.0a) with OCSP stapling active
  • ·Exploitation requires OCSP stapling to be enabled on the TLS server; servers without OCSP stapling enabled are not vulnerable regardless of OpenSSL version
  • ·OpenSSL 1.1.0 series had not been integrated into any Cisco product at time of advisory, limiting exposure on Cisco devices to 1.0.x branches

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_cisco5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.