ISOMAN

CVE

CVE-2016-2105

Integer overflow in the EVP_EncodeUpdate function in crypto/evp/encode.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (heap memory corruption) via a large amount of binary data.

Severity
HIGH
CVSS
7.5
Published
Modified

Linked Releases

References

  1. http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10759
  2. http://lists.apple.com/archives/security-announce/2016/Jul/msg00000.html
  3. http://lists.fedoraproject.org/pipermail/package-announce/2016-May/183457.html
  4. http://lists.fedoraproject.org/pipermail/package-announce/2016-May/183607.html
  5. http://lists.fedoraproject.org/pipermail/package-announce/2016-May/184605.html
  6. http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00001.html
  7. http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00008.html
  8. http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00010.html
  9. http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00011.html
  10. http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00013.html
  11. http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00014.html
  12. http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00015.html
  13. http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00016.html
  14. http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00017.html
  15. http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00018.html
  16. http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00019.html
  17. http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00029.html
  18. http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00030.html
  19. http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00036.html
  20. http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00055.html