← All CVEs

CVE-2016-2105

high · 7.5

Integer overflow in the EVP_EncodeUpdate function in crypto/evp/encode.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (heap memory corruption) via a large amount of binary data.

7.5
CVSS
39.6%
EPSS (exploit prob.)
99th
EPSS percentile
2016-05-05
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses

CWE-190

Affected products

VendorProductAffected versions
redhatenterprise_linux_desktop6.0
redhatenterprise_linux_hpc_node6
redhatenterprise_linux_server6.0
redhatenterprise_linux_workstation6.0
opensuseleap42.1
opensuseopensuse13.2
oraclemysql>= 5.6.0, <= 5.6.30
oraclemysql>= 5.7.0, <= 5.7.12
redhatenterprise_linux_desktop7.0
redhatenterprise_linux_hpc_node7.0
redhatenterprise_linux_hpc_node_eus7.2
redhatenterprise_linux_server7.0
redhatenterprise_linux_server_aus7.2
redhatenterprise_linux_server_eus7.2
redhatenterprise_linux_workstation7.0
applemac_os_x10.11.5
opensslopenssl1.0.1
opensslopenssl1.0.1
opensslopenssl1.0.1
opensslopenssl1.0.1
opensslopenssl1.0.1a
opensslopenssl1.0.1b
opensslopenssl1.0.1c
opensslopenssl1.0.1d
opensslopenssl1.0.1e
opensslopenssl1.0.1f
opensslopenssl1.0.1g
opensslopenssl1.0.1h
opensslopenssl1.0.1i
opensslopenssl1.0.1j
opensslopenssl1.0.1k
opensslopenssl1.0.1l
opensslopenssl1.0.1m
opensslopenssl1.0.1n
opensslopenssl1.0.1o
opensslopenssl1.0.1p
opensslopenssl1.0.1q
opensslopenssl1.0.1r
opensslopenssl1.0.1s
opensslopenssl1.0.2

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2016-2105