OpenSSL CVE-2016-6303 Out of Bounds Write Vulnerability

description-logoDescription

Severity: LowAn overflow can occur in MDC2_Update() either if called directly orthrough the EVP_DigestUpdate() function using MDC2. If an attackeris able to supply very large amounts of input data after a previouscall to EVP_EncryptUpdate() with a partial block then a length checkcan overflow resulting in a heap corruption.The amount of data needed is comparable to SIZE_MAX which is impracticalon most platforms.OpenSSL 1.0.2 users should upgrade to 1.0.2iOpenSSL 1.0.1 users should upgrade to 1.0.1uThis issue was reported to OpenSSL on 11th August 2016 by Shi Lei (Gear Team,Qihoo 360 Inc.). The fix was developed by Stephen Henson of the OpenSSLdevelopment team.

affected-products-logoAffected Applications

OpenSSL

CVE References

CVE-2016-6303