Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-6307

Опубликовано: 26 сент. 2016
Источник: debian
EPSS Средний

Описание

The state-machine implementation in OpenSSL 1.1.0 before 1.1.0a allocates memory before checking for an excessive length, which might allow remote attackers to cause a denial of service (memory consumption) via crafted TLS messages, related to statem/statem.c and statem/statem_lib.c.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
opensslfixed1.1.0a-1experimentalpackage
opensslnot-affectedpackage

Примечания

  • https://git.openssl.org/?p=openssl.git;a=commit;h=c1ef7c971d0bbf117c3c80f65b5875e2e7b024b1

  • https://www.openssl.org/news/secadv/20160922.txt

EPSS

Процентиль: 95%
0.20873
Средний

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 9 лет назад

The state-machine implementation in OpenSSL 1.1.0 before 1.1.0a allocates memory before checking for an excessive length, which might allow remote attackers to cause a denial of service (memory consumption) via crafted TLS messages, related to statem/statem.c and statem/statem_lib.c.

CVSS3: 3.7
redhat
больше 9 лет назад

The state-machine implementation in OpenSSL 1.1.0 before 1.1.0a allocates memory before checking for an excessive length, which might allow remote attackers to cause a denial of service (memory consumption) via crafted TLS messages, related to statem/statem.c and statem/statem_lib.c.

CVSS3: 5.9
nvd
больше 9 лет назад

The state-machine implementation in OpenSSL 1.1.0 before 1.1.0a allocates memory before checking for an excessive length, which might allow remote attackers to cause a denial of service (memory consumption) via crafted TLS messages, related to statem/statem.c and statem/statem_lib.c.

CVSS3: 5.9
github
больше 3 лет назад

The state-machine implementation in OpenSSL 1.1.0 before 1.1.0a allocates memory before checking for an excessive length, which might allow remote attackers to cause a denial of service (memory consumption) via crafted TLS messages, related to statem/statem.c and statem/statem_lib.c.

CVSS3: 5.9
fstec
больше 9 лет назад

Уязвимость компонентов statem/statem.c и statem/statem_lib.c библиотеки OpenSSL, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 95%
0.20873
Средний