Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

Debian 8 DSA-3566-1 Critical: OpenSSL Memory and AES Flaws

debian
Calendar Grey May 3, 2016
Debian Logo
Debian Security Advisory DSA-3578-2 relates to vulnerabilities in OpenSSL, highlighting problems such as buffer overflow and memory corruption.
Several vulnerabilities were discovered in OpenSSL, a Secure Socket Layer toolkit

Summary

CVE-2016-2105

Guido Vranken discovered that an overflow can occur in the function
EVP_EncodeUpdate(), used for Base64 encoding, if an attacker can
supply a large amount of data. This could lead to a heap corruption.

CVE-2016-2106

Guido Vranken discovered that an overflow can occur in the function
EVP_EncryptUpdate() if an attacker can supply a large amount of data.
This could lead to a heap corruption.

CVE-2016-2107

Juraj Somorovsky discovered a padding oracle in the AES CBC cipher
implementation based on the AES-NI instruction set. This could allow
an attacker to decrypt TLS traffic encrypted with one of the cipher
suites based on AES CBC.

CVE-2016-2108

David Benjamin from Google discovered that two separate bugs in the
ASN.1 encoder, related to handling of negative zero integer values
and large universal tags, could lead to an out-of-bounds write.

CVE-2016-2109

Brian Carpenter discovered that when ASN.1 data is read from a BIO
using functio...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: openssl
CVE ID: CVE-2016-2105 CVE-2016-2106 CVE-2016-2107 CVE-2016-2108

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here