NVD
- Id
- 18406
- Name
- CVE-2016-2109
- Description
- The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in the ASN.1 BIO implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (memory consumption) via a short invalid encoding.
- Reject
- CVSS Version
- 2
- CVSS Score
- 7.8
- Severity
- High
- CVSS Base Score
- 7.8
- CVSS Impact Subscore
- 6.9
- CVSS Exploit Subscore
- 10
- CVSS Vector
- (AV:N/AC:L/Au:N/C:N/I:N/A:C)
- Pub Date
- 2017-07-18
- Published
- 2016-05-04
- Modified Date
- 2017-07-12
- Seq
- 2016-2109
Related NVD References
Id | NVD Id | NVD No. | Reference | Actions |
---|---|---|---|---|
102005 | 18406 | CVE-2016-2109 | http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10759 | View |
102006 | 18406 | CVE-2016-2109 | APPLE-SA-2016-07-18-1 | View |
102007 | 18406 | CVE-2016-2109 | SUSE-SU-2016:1206 | View |
102008 | 18406 | CVE-2016-2109 | SUSE-SU-2016:1228 | View |
102009 | 18406 | CVE-2016-2109 | SUSE-SU-2016:1231 | View |
102010 | 18406 | CVE-2016-2109 | SUSE-SU-2016:1233 | View |
102011 | 18406 | CVE-2016-2109 | openSUSE-SU-2016:1237 | View |
102012 | 18406 | CVE-2016-2109 | openSUSE-SU-2016:1238 | View |
102013 | 18406 | CVE-2016-2109 | openSUSE-SU-2016:1239 | View |
102014 | 18406 | CVE-2016-2109 | openSUSE-SU-2016:1240 | View |
102015 | 18406 | CVE-2016-2109 | openSUSE-SU-2016:1241 | View |
102016 | 18406 | CVE-2016-2109 | openSUSE-SU-2016:1242 | View |
102017 | 18406 | CVE-2016-2109 | openSUSE-SU-2016:1243 | View |
102018 | 18406 | CVE-2016-2109 | SUSE-SU-2016:1267 | View |
102019 | 18406 | CVE-2016-2109 | openSUSE-SU-2016:1273 | View |
102020 | 18406 | CVE-2016-2109 | SUSE-SU-2016:1290 | View |
102021 | 18406 | CVE-2016-2109 | SUSE-SU-2016:1360 | View |
102022 | 18406 | CVE-2016-2109 | http://packetstormsecurity.com/files/136912/Slackware-Security-Advisory-openssl-Updates.html | View |
102023 | 18406 | CVE-2016-2109 | RHSA-2016:0722 | View |
102024 | 18406 | CVE-2016-2109 | RHSA-2016:0996 | View |
102025 | 18406 | CVE-2016-2109 | 20160504 Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: May 2016 | View |
102026 | 18406 | CVE-2016-2109 | DSA-3566 | View |
102027 | 18406 | CVE-2016-2109 | http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html | View |
102028 | 18406 | CVE-2016-2109 | http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html | View |
102029 | 18406 | CVE-2016-2109 | http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html | View |
102030 | 18406 | CVE-2016-2109 | http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html | View |
102031 | 18406 | CVE-2016-2109 | http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html | View |
102032 | 18406 | CVE-2016-2109 | http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html | View |
102033 | 18406 | CVE-2016-2109 | 87940 | View |
102034 | 18406 | CVE-2016-2109 | 91787 | View |
102035 | 18406 | CVE-2016-2109 | 1035721 | View |
102036 | 18406 | CVE-2016-2109 | SSA:2016-124-01 | View |
102037 | 18406 | CVE-2016-2109 | USN-2959-1 | View |
102038 | 18406 | CVE-2016-2109 | https://bto.bluecoat.com/security-advisory/sa123 | View |
102039 | 18406 | CVE-2016-2109 | https://git.openssl.org/?p=openssl.git;a=commit;h=c62981390d6cf9e3d612c489b8b77c2913b25807 | View |
102040 | 18406 | CVE-2016-2109 | https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05320149 | View |
102041 | 18406 | CVE-2016-2109 | https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA40202 | View |
102042 | 18406 | CVE-2016-2109 | https://kc.mcafee.com/corporate/index?page=content&id=SB10160 | View |
102043 | 18406 | CVE-2016-2109 | GLSA-201612-16 | View |
102044 | 18406 | CVE-2016-2109 | https://support.apple.com/HT206903 | View |
102045 | 18406 | CVE-2016-2109 | FreeBSD-SA-16:17 | View |
102046 | 18406 | CVE-2016-2109 | https://www.openssl.org/news/secadv/20160503.txt | View |
Related JVN
Id | Name | Title | Summary | Cveinfo Name | Cveinfo Id | Nvdinfo Name | Nvdinfo Id | Cvssv2 | Cvssv3 | Jvnurl | Published Date | Last Updated Date | Actions |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1703 | JVNDB-2016-002476 | OpenSSL の ASN.1 BIO の実装の crypto/asn1/a_d2i_fp.c の asn1_d2i_read_bio 関数におけるサービス運用妨害 (DoS) の脆弱性 | OpenSSL の ASN.1 BIO の実装の crypto/asn1/a_d2i_fp.c の asn1_d2i_read_bio 関数には、サービス運用妨害 (メモリ消費) 状態にされる脆弱性が存在します。 | CVE-2016-2109 | 88615 | CVE-2016-2109 | 18406 | 7.8 | 7.5 | http://jvndb.jvn.jp/ja/contents/2016/JVNDB-2016-002476.html | 2016-05-03 | 2016-11-17 | View |