CVE Vulnerabilities

CVE-2016-0705

Published: Mar 03, 2016 | Modified: Apr 12, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
2.6 LOW
AV:N/AC:H/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

Double free vulnerability in the dsa_priv_decode function in crypto/dsa/dsa_ameth.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a malformed DSA private key.

Affected Software

NameVendorStart VersionEnd Version
MysqlOracle5.6.0 (including)5.6.29 (including)
MysqlOracle5.7.0 (including)5.7.11 (including)
Red Hat Enterprise Linux 6RedHatopenssl-0:1.0.1e-42.el6_7.4*
Red Hat Enterprise Linux 6 SupplementaryRedHatjava-1.8.0-ibm-1:1.8.0.5.20-1jpp.1.el6_10*
Red Hat Enterprise Linux 7RedHatopenssl-1:1.0.1e-51.el7_2.4*
Red Hat Enterprise Linux 7 SupplementaryRedHatjava-1.8.0-ibm-1:1.8.0.5.20-1jpp.1.el7*
Red Hat Satellite 5.8RedHatjava-1.8.0-ibm-1:1.8.0.5.20-1jpp.1.el6_10*
RHEV 3.X Hypervisor and Agents for RHEL-6RedHatrhev-hypervisor7-0:7.2-20160302.1.el6ev*
RHEV 3.X Hypervisor and Agents for RHEL-7RedHatrhev-hypervisor7-0:7.2-20160302.1.el7ev*
Text-Only JBCSRedHat*
OpensslUbuntudevel*
OpensslUbuntuesm-infra-legacy/trusty*
OpensslUbuntuesm-infra/xenial*
OpensslUbuntuprecise*
OpensslUbuntutrusty*
OpensslUbuntutrusty/esm*
OpensslUbuntuupstream*
OpensslUbuntuvivid/stable-phone-overlay*
OpensslUbuntuvivid/ubuntu-core*
OpensslUbuntuwily*
OpensslUbuntuxenial*
Openssl098Ubuntuupstream*

References