Lucene search

K
fortinetFortiGuard LabsFG-IR-16-048
HistoryApr 03, 2017 - 12:00 a.m.

OpenSSL Security Advisory [22 Sept 2016]

2017-04-0300:00:00
FortiGuard Labs
www.fortiguard.com
49

EPSS

0.624

Percentile

97.9%

The OpenSSL project released an advisory on Sept 22nd, 2016, describing 1 High, 1 Medium and 12 Low severity vulnerabilities, as listed below: * OCSP Status Request extension unbounded memory growth (CVE-2016-6304) * SSL_peek() hang on empty record (CVE-2016-6305) * SWEET32 Mitigation (CVE-2016-2183) * OOB write in MDC2_Update() (CVE-2016-6303) * Malformed SHA512 ticket DoS (CVE-2016-6302) * OOB write in BN_bn2dec() (CVE-2016-2182) * OOB read in TS_OBJ_print_bio() (CVE-2016-2180) * Pointer arithmetic undefined behaviour (CVE-2016-2177) * Constant time flag not preserved in DSA signing (CVE-2016-2178) * DTLS buffered message DoS (CVE-2016-2179) * DTLS replay protection DoS (CVE-2016-2181) * Certificate message OOB reads (CVE-2016-6306) * Excessive allocation of memory in tls_get_message_header() (CVE-2016-6307) * Excessive allocation of memory in dtls1_preprocess_fragment() (CVE-2016-6308)