UBUNTU-CVE-2016-8610
Dashboard / Vulnerabilities / UBUNTU-CVE-2016-8610
UBUNTU-CVE-2016-8610
Summary:
Details: A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote attacker could use this flaw to make a TLS/SSL server consume an excessive amount of CPU and fail to accept connections from other clients.
References: https://ubuntu.com/security/CVE-2016-8610, http://www.openwall.com/lists/oss-security/2016/10/24/3, http://security.360.cn/cve/CVE-2016-8610/, https://ubuntu.com/security/notices/USN-3181-1, https://ubuntu.com/security/notices/USN-3183-1, https://ubuntu.com/security/notices/USN-3183-2, https://www.cve.org/CVERecord?id=CVE-2016-8610
Affected packages
Package
Name: gnutls26
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
