UBUNTU-CVE-2016-2177
Dashboard / Vulnerabilities / UBUNTU-CVE-2016-2177
UBUNTU-CVE-2016-2177
Summary:
Details: OpenSSL through 1.0.2h incorrectly uses pointer arithmetic for heap-buffer boundary checks, which might allow remote attackers to cause a denial of service (integer overflow and application crash) or possibly have unspecified other impact by leveraging unexpected malloc behavior, related to s3_srvr.c, ssl_sess.c, and t1_lib.c.
References: https://ubuntu.com/security/CVE-2016-2177, https://www.openssl.org/news/secadv/20160922.txt, https://www.openssl.org/blog/blog/2016/06/27/undefined-pointer-arithmetic/, https://ubuntu.com/security/notices/USN-3087-1, https://ubuntu.com/security/notices/USN-3181-1, https://www.cve.org/CVERecord?id=CVE-2016-2177
Affected packages
Package
Name: openssl
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
