CVE-2016-2108
critical · 9.8The ASN.1 implementation in OpenSSL before 1.0.1o and 1.0.2 before 1.0.2c allows remote attackers to execute arbitrary code or cause a denial of service (buffer underflow and memory corruption) via an ANY field in crafted serialized data, aka the "negative zero" issue.
9.8
CVSS
77.9%
EPSS (exploit prob.)
100th
EPSS percentile
2016-05-05
Published
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-119
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| redhat | enterprise_linux_desktop | 6.0 |
| redhat | enterprise_linux_hpc_node | 6.0 |
| redhat | enterprise_linux_server | 6.0 |
| redhat | enterprise_linux_workstation | 6.0 |
| openssl | openssl | <= 1.0.1n |
| openssl | openssl | 1.0.2 |
| openssl | openssl | 1.0.2 |
| openssl | openssl | 1.0.2 |
| openssl | openssl | 1.0.2 |
| openssl | openssl | 1.0.2a |
| openssl | openssl | 1.0.2b |
| redhat | enterprise_linux_desktop | 7.0 |
| redhat | enterprise_linux_hpc_node | 7.0 |
| redhat | enterprise_linux_hpc_node_eus | 7.2 |
| redhat | enterprise_linux_server | 7.0 |
| redhat | enterprise_linux_server_aus | 7.2 |
| redhat | enterprise_linux_server_eus | 7.2 |
| redhat | enterprise_linux_workstation | 7.0 |
| android | 4.0 | |
| android | 4.0.1 | |
| android | 4.0.2 | |
| android | 4.0.3 | |
| android | 4.0.4 | |
| android | 4.1 | |
| android | 4.1.2 | |
| android | 4.2 | |
| android | 4.2.1 | |
| android | 4.2.2 | |
| android | 4.3 | |
| android | 4.3.1 | |
| android | 4.4 | |
| android | 4.4.1 | |
| android | 4.4.2 | |
| android | 4.4.3 | |
| android | 5.0 | |
| android | 5.0.1 | |
| android | 5.1 | |
| android | 5.1.0 | |
| android | 6.0 | |
| android | 6.0.1 |
Check a specific version with /api/v1/cve/match.
References
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10759
- http://lists.apple.com/archives/security-announce/2016/Jul/msg00000.html
- http://lists.fedoraproject.org/pipermail/package-announce/2016-May/183457.html
- http://lists.fedoraproject.org/pipermail/package-announce/2016-May/183607.html
- http://lists.fedoraproject.org/pipermail/package-announce/2016-May/184605.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00001.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00008.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00011.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00013.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00014.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00015.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00016.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00017.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00018.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00019.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00029.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00030.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00036.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00055.html
- http://packetstormsecurity.com/files/136912/Slackware-Security-Advisory-openssl-Updates.html
- http://rhn.redhat.com/errata/RHSA-2016-0722.html
- http://rhn.redhat.com/errata/RHSA-2016-0996.html
- http://rhn.redhat.com/errata/RHSA-2016-2056.html
- http://rhn.redhat.com/errata/RHSA-2016-2073.html
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2016-2108