IM
IronMonkey Threat Research

CVE-2016-6306 MEDIUM

Published: 2016-09-26 | Last Modified: 2026-06-17 | Status: Modified

Description

The certificate parser in OpenSSL before 1.0.1u and 1.0.2 before 1.0.2i might allow remote attackers to cause a denial of service (out-of-bounds read) via crafted certificate operations, related to s3_clnt.c and s3_srvr.c.

Additional Descriptions (1)

El analizador certificado en OpenSSL en versiones anteriores a 1.0.1u y 1.0.2 en versiones anteriores a 1.0.2i podría permitir a atacantes remotos provocar una denegación de servicio (lectura fuera de rango) a través de operaciones certificadas manipuladas, relacionado con s3_clnt.c y s3_srvr.c.

CVSS Metrics

Base Score: 5.9 (MEDIUM)

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack VectorNETWORK
Attack ComplexityHIGH
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactNONE
Integrity ImpactNONE
Availability ImpactHIGH

Source: [email protected]

Type: Primary

Exploitability Score: 2.2

Impact Score: 3.6

Base Score: 4.3 (MEDIUM)

AV:N/AC:M/Au:N/C:N/I:N/A:P

Access VectorNETWORK
Access ComplexityMEDIUM
AuthenticationNONE
Confidentiality ImpactNONE
Integrity ImpactNONE
Availability ImpactPARTIAL

Source: [email protected]

Type: Primary

Exploitability Score: 8.6

Impact Score: 2.9

Weaknesses

Source Type Description
[email protected] Primary
en CWE-125

Affected Products

Vendor Product Version Update Type
openssl openssl 1.0.1 <built-in method update of dict object at 0x72a9ccd280c0> Application
openssl openssl 1.0.1 <built-in method update of dict object at 0x72a9ccd2ba40> Application
openssl openssl 1.0.1 <built-in method update of dict object at 0x72a9ccd29d00> Application
openssl openssl 1.0.1 <built-in method update of dict object at 0x72a9b0904240> Application
openssl openssl 1.0.1a <built-in method update of dict object at 0x72a9ccd28d00> Application
openssl openssl 1.0.1b <built-in method update of dict object at 0x72a9ccd2b200> Application
openssl openssl 1.0.1c <built-in method update of dict object at 0x72a9b0905b40> Application
openssl openssl 1.0.1d <built-in method update of dict object at 0x72a9b0904dc0> Application
openssl openssl 1.0.1e <built-in method update of dict object at 0x72a9ccd29100> Application
openssl openssl 1.0.1f <built-in method update of dict object at 0x72a9ccd2b280> Application
openssl openssl 1.0.1g <built-in method update of dict object at 0x72a9cdf31e00> Application
openssl openssl 1.0.1h <built-in method update of dict object at 0x72a9ccd2bf80> Application
openssl openssl 1.0.1i <built-in method update of dict object at 0x72a9ccd29c40> Application
openssl openssl 1.0.1j <built-in method update of dict object at 0x72a9b0b68200> Application
openssl openssl 1.0.1k <built-in method update of dict object at 0x72a9ccd28c40> Application
openssl openssl 1.0.1l <built-in method update of dict object at 0x72a9ccd2ac00> Application
openssl openssl 1.0.1m <built-in method update of dict object at 0x72a9ccd2bac0> Application
openssl openssl 1.0.1n <built-in method update of dict object at 0x72a9ccd29280> Application
openssl openssl 1.0.1o <built-in method update of dict object at 0x72a9b0906dc0> Application
openssl openssl 1.0.1p <built-in method update of dict object at 0x72a9b0904a00> Application
openssl openssl 1.0.1q <built-in method update of dict object at 0x72a9cc5dd580> Application
openssl openssl 1.0.1r <built-in method update of dict object at 0x72a9ccd2b780> Application
openssl openssl 1.0.1s <built-in method update of dict object at 0x72a9b0905480> Application
openssl openssl 1.0.1t <built-in method update of dict object at 0x72a9b0b68380> Application
hp icewall_federation_agent 3.0 <built-in method update of dict object at 0x72a9b0907ec0> Application
hp icewall_mcrp 3.0 <built-in method update of dict object at 0x72a9cc6d8100> Application
hp icewall_sso 10.0 <built-in method update of dict object at 0x72a9cc5de2c0> Application
hp icewall_sso 10.0 <built-in method update of dict object at 0x72a9b09057c0> Application
hp icewall_sso_agent_option 10.0 <built-in method update of dict object at 0x72a9b0b395c0> Application
novell suse_linux_enterprise_module_for_web_scripting 12.0 <built-in method update of dict object at 0x72a9b0b3afc0> Operating System
openssl openssl 1.0.2 <built-in method update of dict object at 0x72a9b0b3bdc0> Application
openssl openssl 1.0.2 <built-in method update of dict object at 0x72a9cd084100> Application
openssl openssl 1.0.2 <built-in method update of dict object at 0x72a9cd085ac0> Application
openssl openssl 1.0.2 <built-in method update of dict object at 0x72a9cd0865c0> Application
openssl openssl 1.0.2a <built-in method update of dict object at 0x72a9b0c65080> Application
openssl openssl 1.0.2b <built-in method update of dict object at 0x72a9b0c64280> Application
openssl openssl 1.0.2c <built-in method update of dict object at 0x72a9cd06f200> Application
openssl openssl 1.0.2d <built-in method update of dict object at 0x72a9b0c67280> Application
openssl openssl 1.0.2e <built-in method update of dict object at 0x72a9b0c672c0> Application
openssl openssl 1.0.2f <built-in method update of dict object at 0x72a9b0c65a00> Application
openssl openssl 1.0.2h <built-in method update of dict object at 0x72a9cd06dcc0> Application
nodejs node.js * <built-in method update of dict object at 0x72a9b0c65c80> Application
nodejs node.js * <built-in method update of dict object at 0x72a9b0c67a40> Application
nodejs node.js * <built-in method update of dict object at 0x72a9cd06ee00> Application
nodejs node.js * <built-in method update of dict object at 0x72a9b0c648c0> Application
nodejs node.js * <built-in method update of dict object at 0x72a9b0c64f80> Application
nodejs node.js * <built-in method update of dict object at 0x72a9b0c64100> Application
debian debian_linux 8.0 <built-in method update of dict object at 0x72a9cd06f7c0> Operating System
canonical ubuntu_linux 12.04 <built-in method update of dict object at 0x72a9b0c64e00> Operating System
canonical ubuntu_linux 14.04 <built-in method update of dict object at 0x72a9b0c67600> Operating System
canonical ubuntu_linux 16.04 <built-in method update of dict object at 0x72a9b0c675c0> Operating System

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:openssl:openssl:1.0.1:*:*:*:*:*:*:*
Yes cpe:2.3:a:openssl:openssl:1.0.1:beta1:*:*:*:*:*:*
Yes cpe:2.3:a:openssl:openssl:1.0.1:beta2:*:*:*:*:*:*
Yes cpe:2.3:a:openssl:openssl:1.0.1:beta3:*:*:*:*:*:*
Yes cpe:2.3:a:openssl:openssl:1.0.1a:*:*:*:*:*:*:*
Yes cpe:2.3:a:openssl:openssl:1.0.1b:*:*:*:*:*:*:*
Yes cpe:2.3:a:openssl:openssl:1.0.1c:*:*:*:*:*:*:*
Yes cpe:2.3:a:openssl:openssl:1.0.1d:*:*:*:*:*:*:*
Yes cpe:2.3:a:openssl:openssl:1.0.1e:*:*:*:*:*:*:*
Yes cpe:2.3:a:openssl:openssl:1.0.1f:*:*:*:*:*:*:*
Yes cpe:2.3:a:openssl:openssl:1.0.1g:*:*:*:*:*:*:*
Yes cpe:2.3:a:openssl:openssl:1.0.1h:*:*:*:*:*:*:*
Yes cpe:2.3:a:openssl:openssl:1.0.1i:*:*:*:*:*:*:*
Yes cpe:2.3:a:openssl:openssl:1.0.1j:*:*:*:*:*:*:*
Yes cpe:2.3:a:openssl:openssl:1.0.1k:*:*:*:*:*:*:*
Yes cpe:2.3:a:openssl:openssl:1.0.1l:*:*:*:*:*:*:*
Yes cpe:2.3:a:openssl:openssl:1.0.1m:*:*:*:*:*:*:*
Yes cpe:2.3:a:openssl:openssl:1.0.1n:*:*:*:*:*:*:*
Yes cpe:2.3:a:openssl:openssl:1.0.1o:*:*:*:*:*:*:*
Yes cpe:2.3:a:openssl:openssl:1.0.1p:*:*:*:*:*:*:*
Yes cpe:2.3:a:openssl:openssl:1.0.1q:*:*:*:*:*:*:*
Yes cpe:2.3:a:openssl:openssl:1.0.1r:*:*:*:*:*:*:*
Yes cpe:2.3:a:openssl:openssl:1.0.1s:*:*:*:*:*:*:*
Yes cpe:2.3:a:openssl:openssl:1.0.1t:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:hp:icewall_federation_agent:3.0:*:*:*:*:*:*:*
Yes cpe:2.3:a:hp:icewall_mcrp:3.0:*:*:*:*:*:*:*
Yes cpe:2.3:a:hp:icewall_sso:10.0:*:*:*:certd:*:*:*
Yes cpe:2.3:a:hp:icewall_sso:10.0:*:*:*:dfw:*:*:*
Yes cpe:2.3:a:hp:icewall_sso_agent_option:10.0:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:novell:suse_linux_enterprise_module_for_web_scripting:12.0:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:openssl:openssl:1.0.2:*:*:*:*:*:*:*
Yes cpe:2.3:a:openssl:openssl:1.0.2:beta1:*:*:*:*:*:*
Yes cpe:2.3:a:openssl:openssl:1.0.2:beta2:*:*:*:*:*:*
Yes cpe:2.3:a:openssl:openssl:1.0.2:beta3:*:*:*:*:*:*
Yes cpe:2.3:a:openssl:openssl:1.0.2a:*:*:*:*:*:*:*
Yes cpe:2.3:a:openssl:openssl:1.0.2b:*:*:*:*:*:*:*
Yes cpe:2.3:a:openssl:openssl:1.0.2c:*:*:*:*:*:*:*
Yes cpe:2.3:a:openssl:openssl:1.0.2d:*:*:*:*:*:*:*
Yes cpe:2.3:a:openssl:openssl:1.0.2e:*:*:*:*:*:*:*
Yes cpe:2.3:a:openssl:openssl:1.0.2f:*:*:*:*:*:*:*
Yes cpe:2.3:a:openssl:openssl:1.0.2h:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:*
Yes cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:*
Yes cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:*
Yes cpe:2.3:a:nodejs:node.js:*:*:*:*:lts:*:*:*
Yes cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:*
Yes cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:-:*:*:*
Yes cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*
Yes cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*

References

Notification
Message here