Vulnerability Description
The certificate parser in OpenSSL before 1.0.1u and 1.0.2 before 1.0.2i might allow remote attackers to cause a denial of service (out-of-bounds read) via crafted certificate operations, related to s3_clnt.c and s3_srvr.c.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openssl | Openssl | 1.0.1 |
| Hp | Icewall Federation Agent | 3.0 |
| Hp | Icewall Mcrp | 3.0 |
| Hp | Icewall Sso | 10.0 |
| Hp | Icewall Sso Agent Option | 10.0 |
| Novell | Suse Linux Enterprise Module For Web Scripting | 12.0 |
| Nodejs | Node.Js | >= 0.10.0, < 0.10.47 |
| Debian | Debian Linux | 8.0 |
| Canonical | Ubuntu Linux | 12.04 |
Related Weaknesses (CWE)
References
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10759Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-09/msg00022.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-09/msg00023.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-09/msg00024.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-09/msg00031.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00005.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00011.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00012.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00013.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00021.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00029.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2018-02/msg00032.htmlMailing ListThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-1940.htmlThird Party Advisory
FAQ
What is CVE-2016-6306?
CVE-2016-6306 is a vulnerability with a CVSS score of 5.9 (MEDIUM). The certificate parser in OpenSSL before 1.0.1u and 1.0.2 before 1.0.2i might allow remote attackers to cause a denial of service (out-of-bounds read) via crafted certificate operations, related to s3...
How severe is CVE-2016-6306?
CVE-2016-6306 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-6306?
Check the references section above for vendor advisories and patch information. Affected products include: Openssl Openssl, Hp Icewall Federation Agent, Hp Icewall Mcrp, Hp Icewall Sso, Hp Icewall Sso Agent Option.