Severity
7.5HIGHNVD
EPSS
1.1%
top 22.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 4
Latest updateMay 17

Description

In OpenSSL 1.1.0 before 1.1.0c, applications parsing invalid CMS structures can crash with a NULL pointer dereference. This is caused by a bug in the handling of the ASN.1 CHOICE type in OpenSSL 1.1.0 which can result in a NULL value being passed to the structure callback if an attempt is made to free certain invalid encodings. Only CHOICE structures using a callback which do not handle NULL value are affected.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

debiandebian/openssl< openssl 1.1.0c-1 (bookworm)
Debianopenssl/openssl< 1.1.0c-1+3
CVEListV5openssl/opensslopenssl-1.1.0, openssl-1.1.0a, openssl-1.1.0b+2
NVDopenssl/openssl1.1.0, 1.1.0a, 1.1.0b+2

🔴Vulnerability Details

2
GHSA
GHSA-hp2v-mmp5-5mcx: In OpenSSL 12022-05-17
OSV
CVE-2016-7053: In OpenSSL 12017-05-04

📋Vendor Advisories

4
Cisco
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: November 20162016-11-14
Red Hat
openssl: CMS Null dereference vulnerability2016-11-10
Debian
CVE-2016-7053: openssl - In OpenSSL 1.1.0 before 1.1.0c, applications parsing invalid CMS structures can ...2016
Cisco
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: November 2016

💬Community

1
Bugzilla
CVE-2016-7053 openssl: CMS Null dereference vulnerability2016-11-10
CVE-2016-7053 — NULL Pointer Dereference in Openssl | cvebase