OpenSSL CVE-2016-2182 Out of Bounds Write Vulnerability

description-logoDescription

Severity: LowThe function BN_bn2dec() does not check the return value of BN_div_word().This can cause an OOB write if an application uses this function with anoverly large BIGNUM. This could be a problem if an overly large certificateor CRL is printed out from an untrusted source. TLS is not affected becauserecord limits will reject an oversized certificate before it is parsed.OpenSSL 1.0.2 users should upgrade to 1.0.2iOpenSSL 1.0.1 users should upgrade to 1.0.1uThis issue was reported to OpenSSL on 2nd August 2016 by Shi Lei (Gear Team,Qihoo 360 Inc.). The fix was developed by Stephen Henson of the OpenSSLdevelopment team.

affected-products-logoAffected Applications

OpenSSL

CVE References

CVE-2016-2182