Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-6305

Опубликовано: 26 сент. 2016
Источник: debian
EPSS Средний

Описание

The ssl3_read_bytes function in record/rec_layer_s3.c in OpenSSL 1.1.0 before 1.1.0a allows remote attackers to cause a denial of service (infinite loop) by triggering a zero-length record in an SSL_peek call.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
opensslfixed1.1.0a-1experimentalpackage
opensslnot-affectedpackage

Примечания

  • https://www.openssl.org/news/secadv/20160922.txt

  • Fixed in 1.1.0a

EPSS

Процентиль: 97%
0.15997
Средний

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 10 лет назад

The ssl3_read_bytes function in record/rec_layer_s3.c in OpenSSL 1.1.0 before 1.1.0a allows remote attackers to cause a denial of service (infinite loop) by triggering a zero-length record in an SSL_peek call.

CVSS3: 5.9
redhat
почти 10 лет назад

The ssl3_read_bytes function in record/rec_layer_s3.c in OpenSSL 1.1.0 before 1.1.0a allows remote attackers to cause a denial of service (infinite loop) by triggering a zero-length record in an SSL_peek call.

CVSS3: 7.5
nvd
почти 10 лет назад

The ssl3_read_bytes function in record/rec_layer_s3.c in OpenSSL 1.1.0 before 1.1.0a allows remote attackers to cause a denial of service (infinite loop) by triggering a zero-length record in an SSL_peek call.

CVSS3: 7.5
github
больше 4 лет назад

The ssl3_read_bytes function in record/rec_layer_s3.c in OpenSSL 1.1.0 before 1.1.0a allows remote attackers to cause a denial of service (infinite loop) by triggering a zero-length record in an SSL_peek call.

CVSS3: 7.5
fstec
почти 10 лет назад

Уязвимость функции ssl3_read_bytes (record/rec_layer_s3.c) библиотеки OpenSSL, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 97%
0.15997
Средний