Lucene search

K
f5F5F5:K75152412
HistoryMay 19, 2016 - 12:00 a.m.

K75152412 : OpenSSL vulnerability CVE-2016-2108

2016-05-1900:00:00
my.f5.com
45

AI Score

9.8

Confidence

High

EPSS

0.895

Percentile

98.8%

Security Advisory Description

The ASN.1 implementation in OpenSSL before 1.0.1o and 1.0.2 before 1.0.2c allows remote attackers to execute arbitrary code or cause a denial of service (buffer underflow and memory corruption) via an ANY field in crafted serialized data, aka the “negative zero” issue. (CVE-2016-2108)
Impact
A successful attack can create memory corruption, which may result in processes restarting or arbitrary code execution.