CVE-2016-2176
Summary
| CVE | CVE-2016-2176 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-05-05 01:59:00 UTC |
| Updated | 2023-11-07 02:31:00 UTC |
| Description | The X509_NAME_oneline function in crypto/x509/x509_obj.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to obtain sensitive information from process stack memory or cause a denial of service (buffer over-read) via crafted EBCDIC ASN.1 data. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Oracle Solaris Bulletin - April 2016 |
CONFIRM |
www.oracle.com |
|
| About the security content of OS X El Capitan v10.11.6 and Security Update 2016-004 - Apple Support |
CONFIRM |
support.apple.com |
|
| Slackware Security Advisory - openssl Updates ≈ Packet Storm |
MISC |
packetstormsecurity.com |
|
| Oracle Critical Patch Update - July 2016 |
CONFIRM |
www.oracle.com |
|
| APPLE-SA-2016-07-18-1 OS X El Capitan v10.11.6 and Security Update 2016-004 |
APPLE |
lists.apple.com |
|
| Oracle July 2016 Critical Patch Update Multiple Vulnerabilities |
BID |
www.securityfocus.com |
|
| Broadcom Support Portal |
CONFIRM |
bto.bluecoat.com |
|
| CPU July 2018 |
CONFIRM |
www.oracle.com |
|
| git.openssl.org Git - openssl.git/commit |
|
git.openssl.org |
|
| Oracle Critical Patch Update - October 2016 |
CONFIRM |
www.oracle.com |
|
| [R7] LCE 4.8.1 Fixes Multiple Vulnerabilities - Security Advisory | Tenable™ |
CONFIRM |
www.tenable.com |
|
| OpenSSL CVE-2016-2176 Information Disclosure Vulnerability |
BID |
www.securityfocus.com |
|
| Document Display | HPE Support Center |
CONFIRM |
h20566.www2.hpe.com |
|
| OpenSSL: Multiple vulnerabilities (GLSA 201612-16) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| The Slackware Linux Project: Slackware Security Advisories |
SLACKWARE |
www.slackware.com |
|
| OpenSSL Multiple Bugs Let Remote Users Decrypt Data, Deny Service, Obtain Potentially Sensitive Information, and Potentially Execute Arbitrary Code - SecurityTracker |
SECTRACK |
www.securitytracker.com |
|
| cert-portal.siemens.com/productcert/pdf/ssa-412672.pdf |
CONFIRM |
cert-portal.siemens.com |
|
| Document Display | HPE Support Center |
CONFIRM |
h20566.www2.hpe.com |
|
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: May 2016 |
CISCO |
tools.cisco.com |
|
| www.openssl.org/news/secadv/20160503.txt |
CONFIRM |
www.openssl.org |
Vendor Advisory |
| May 2016 OpenSSL Vulnerabilities in Multiple NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| McAfee Security Bulletin: McAfee product updates fix vulnerabilities in OpenSSL that can allow an attacker to decrypt the traffic, corrupt the heap, and cause a denial of service |
CONFIRM |
kc.mcafee.com |
|
| Public KB - SA40202 - [Pulse Secure] May 3rd 2016 OpenSSL Security Advisory |
CONFIRM |
kb.pulsesecure.net |
|
| git.openssl.org Git - openssl.git/commit |
CONFIRM |
git.openssl.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 43588 Huawei Open Secure Sockets Layer (OpenSSL) Multiple Vulnerabilities (huawei-sa-20160706-01-openssl)
- 591280 Siemens SCALANCE X-200RNA Switch Devices Denial of Service (DoS) Multiple Vulnerabilities (ICSA-22-349-21, SSA-412672)