← All CVEs

CVE-2016-2180

high · 7.5

The TS_OBJ_print_bio function in crypto/ts/ts_lib.c in the X.509 Public Key Infrastructure Time-Stamp Protocol (TSP) implementation in OpenSSL through 1.0.2h allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted time-stamp file that is mishandled by the "openssl ts" command.

7.5
CVSS
28.5%
EPSS (exploit prob.)
98th
EPSS percentile
2016-08-01
Published

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses

CWE-125

Affected products

VendorProductAffected versions
opensslopenssl1.0.1
opensslopenssl1.0.1a
opensslopenssl1.0.1b
opensslopenssl1.0.1c
opensslopenssl1.0.1d
opensslopenssl1.0.1e
opensslopenssl1.0.1f
opensslopenssl1.0.1g
opensslopenssl1.0.1h
opensslopenssl1.0.1i
opensslopenssl1.0.1j
opensslopenssl1.0.1k
opensslopenssl1.0.1l
opensslopenssl1.0.1m
opensslopenssl1.0.1n
opensslopenssl1.0.1o
opensslopenssl1.0.1p
opensslopenssl1.0.1q
opensslopenssl1.0.1r
opensslopenssl1.0.1s
opensslopenssl1.0.1t
opensslopenssl1.0.2
opensslopenssl1.0.2a
opensslopenssl1.0.2b
opensslopenssl1.0.2c
opensslopenssl1.0.2d
opensslopenssl1.0.2e
opensslopenssl1.0.2f
opensslopenssl1.0.2g
opensslopenssl1.0.2h
oraclelinux6
oraclelinux7

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2016-2180