vulnerability

SUSE: CVE-2016-0799: SUSE Linux Security Advisory

Severity
10
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
Published
Mar 1, 2016
Added
Mar 3, 2016
Modified
Feb 4, 2022

Description

The fmtstr function in crypto/bio/b_print.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g improperly calculates string lengths, which allows remote attackers to cause a denial of service (overflow and out-of-bounds read) or possibly have unspecified other impact via a long string, as demonstrated by a large amount of ASN.1 data, a different vulnerability than CVE-2016-2842.

Solutions

suse-upgrade-compat-openssl097gsuse-upgrade-compat-openssl097g-32bitsuse-upgrade-libopenssl-1_0_0-develsuse-upgrade-libopenssl-develsuse-upgrade-libopenssl0_9_8suse-upgrade-libopenssl0_9_8-32bitsuse-upgrade-libopenssl0_9_8-hmacsuse-upgrade-libopenssl0_9_8-hmac-32bitsuse-upgrade-libopenssl0_9_8-x86suse-upgrade-libopenssl1-develsuse-upgrade-libopenssl1_0_0suse-upgrade-libopenssl1_0_0-32bitsuse-upgrade-libopenssl1_0_0-hmacsuse-upgrade-libopenssl1_0_0-hmac-32bitsuse-upgrade-libopenssl1_0_0-x86suse-upgrade-opensslsuse-upgrade-openssl-1_0_0suse-upgrade-openssl-1_0_0-docsuse-upgrade-openssl-docsuse-upgrade-openssl1suse-upgrade-openssl1-docsuse-upgrade-sles11sp4-docker-imagesuse-upgrade-sles12-docker-imagesuse-upgrade-sles12sp1-docker-image

References

    Title
    NEW

    Explore Exposure Command

    Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.