Lucene search

K
f5F5F5:K23230229
HistoryMay 07, 2016 - 12:00 a.m.

K23230229 : OpenSSL vulnerability CVE-2016-2109

2016-05-0700:00:00
my.f5.com
39

8.2 High

AI Score

Confidence

High

0.826 High

EPSS

Percentile

98.4%

Security Advisory Description

The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in the ASN.1 BIO implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (memory consumption) via a short invalid encoding. (CVE-2016-2109)
Impact
Specially crafted ASN.1 files, loaded onto the BIG-IP system by an authenticated user, can be read and may cause excessive resource consumption. This vulnerability may lead to processes restarting.