CVE Vulnerabilities

CVE-2016-0798

Published: Mar 03, 2016 | Modified: Apr 12, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
7.8 HIGH
AV:N/AC:L/Au:N/C:N/I:N/A:C
RedHat/V2
4.3 LOW
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

Memory leak in the SRP_VBASE_get_by_user implementation in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g allows remote attackers to cause a denial of service (memory consumption) by providing an invalid username in a connection attempt, related to apps/s_server.c and crypto/srp/srp_vfy.c.

Affected Software

NameVendorStart VersionEnd Version
OpensslOpenssl1.0.1 (including)1.0.1 (including)
OpensslOpenssl1.0.1-beta1 (including)1.0.1-beta1 (including)
OpensslOpenssl1.0.1-beta2 (including)1.0.1-beta2 (including)
OpensslOpenssl1.0.1-beta3 (including)1.0.1-beta3 (including)
OpensslOpenssl1.0.1a (including)1.0.1a (including)
OpensslOpenssl1.0.1b (including)1.0.1b (including)
OpensslOpenssl1.0.1c (including)1.0.1c (including)
OpensslOpenssl1.0.1d (including)1.0.1d (including)
OpensslOpenssl1.0.1e (including)1.0.1e (including)
OpensslOpenssl1.0.1f (including)1.0.1f (including)
OpensslOpenssl1.0.1g (including)1.0.1g (including)
OpensslOpenssl1.0.1h (including)1.0.1h (including)
OpensslOpenssl1.0.1i (including)1.0.1i (including)
OpensslOpenssl1.0.1j (including)1.0.1j (including)
OpensslOpenssl1.0.1k (including)1.0.1k (including)
OpensslOpenssl1.0.1l (including)1.0.1l (including)
OpensslOpenssl1.0.1m (including)1.0.1m (including)
OpensslOpenssl1.0.1n (including)1.0.1n (including)
OpensslOpenssl1.0.1o (including)1.0.1o (including)
OpensslOpenssl1.0.1p (including)1.0.1p (including)
OpensslOpenssl1.0.1q (including)1.0.1q (including)
OpensslOpenssl1.0.1r (including)1.0.1r (including)
OpensslOpenssl1.0.2 (including)1.0.2 (including)
OpensslOpenssl1.0.2-beta1 (including)1.0.2-beta1 (including)
OpensslOpenssl1.0.2-beta2 (including)1.0.2-beta2 (including)
OpensslOpenssl1.0.2-beta3 (including)1.0.2-beta3 (including)
OpensslOpenssl1.0.2a (including)1.0.2a (including)
OpensslOpenssl1.0.2b (including)1.0.2b (including)
OpensslOpenssl1.0.2c (including)1.0.2c (including)
OpensslOpenssl1.0.2d (including)1.0.2d (including)
OpensslOpenssl1.0.2e (including)1.0.2e (including)
OpensslOpenssl1.0.2f (including)1.0.2f (including)
OpensslUbuntudevel*
OpensslUbuntuesm-infra-legacy/trusty*
OpensslUbuntuesm-infra/xenial*
OpensslUbuntuprecise*
OpensslUbuntutrusty*
OpensslUbuntutrusty/esm*
OpensslUbuntuvivid/stable-phone-overlay*
OpensslUbuntuvivid/ubuntu-core*
OpensslUbuntuwily*
OpensslUbuntuxenial*

References