CVE-2016-7053
Dashboard / Vulnerabilities / CVE-2016-7053
CVE-2016-7053
Published: 4 May 2017Last Modified: 8 Jul 2026
Summary:
Details: In OpenSSL 1.1.0 before 1.1.0c, applications parsing invalid CMS structures can crash with a NULL pointer dereference. This is caused by a bug in the handling of the ASN.1 CHOICE type in OpenSSL 1.1.0 which can result in a NULL value being passed to the structure callback if an attempt is made to free certain invalid encodings. Only CHOICE structures using a callback which do not handle NULL value are affected.
References: http://www.securitytracker.com/id/1037261, https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03744en_us, http://www.securityfocus.com/bid/94244, https://www.openssl.org/news/secadv/20161110.txt
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
Introduced- 7ea5bd2b52d0e81eaef3d109b3b12545306f201c
Fixed -None
Affected versions
1.1.0
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
