cbcvebase.
CVE-2016-7052
published 2016-09-26

CVE-2016-7052: crypto/x509/x509_vfy.c in OpenSSL 1.0.2i allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by triggering a…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
crypto/x509/x509_vfy.c in OpenSSL 1.0.2i allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by triggering a CRL operation.

Affected

10 ranges
VendorProductVersion rangeFixed in
debianopenssl< openssl 1.0.2j-1 (bookworm)openssl 1.0.2j-1 (bookworm)
nodejsnode.js4.0.0 – 4.1.2
nodejsnode.js>= 4.2.0 < 4.6.04.6.0
nodejsnode.js>= 6.0.0 < 6.7.06.7.0
novellsuse_linux_enterprise_module_for_web_scripting
opensslopenssl
opensslopenssl>= 0 < 1.0.2j-11.0.2j-1
opensslopenssl>= 0 < 1.0.2j-11.0.2j-1
opensslopenssl>= 0 < 1.0.2j-11.0.2j-1
opensslopenssl>= 0 < 1.0.2j-11.0.2j-1

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH