Lucene search

K
f5F5F5:K09422508
HistoryOct 19, 2016 - 12:00 a.m.

K09422508 : OpenSSL vulnerabilities CVE-2016-6307 and CVE-2016-6308

2016-10-1900:00:00
my.f5.com
38

AI Score

7.1

Confidence

High

EPSS

0.624

Percentile

97.8%

Security Advisory Description

The state-machine implementation in OpenSSL 1.1.0 before 1.1.0a allocates memory before checking for an excessive length, which might allow remote attackers to cause a denial of service (memory consumption) via crafted TLS messages, related to statem/statem.c and statem/statem_lib.c.

statem/statem_dtls.c in the DTLS implementation in OpenSSL 1.1.0 before 1.1.0a allocates memory before checking for an excessive length, which might allow remote attackers to cause a denial of service (memory consumption) via crafted DTLS messages.
Impact
There is no impact; F5 products are not affected by this vulnerability.