CVE Vulnerabilities

CVE-2016-2106

Published: May 05, 2016 | Modified: Apr 12, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
5.1 MODERATE
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V3
5.6 MODERATE
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

Integer overflow in the EVP_EncryptUpdate function in crypto/evp/evp_enc.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (heap memory corruption) via a large amount of data.

Affected Software

NameVendorStart VersionEnd Version
OpensslOpenssl*1.0.1s (including)
OpensslOpenssl1.0.2 (including)1.0.2 (including)
OpensslOpenssl1.0.2-beta1 (including)1.0.2-beta1 (including)
OpensslOpenssl1.0.2-beta2 (including)1.0.2-beta2 (including)
OpensslOpenssl1.0.2-beta3 (including)1.0.2-beta3 (including)
OpensslOpenssl1.0.2a (including)1.0.2a (including)
OpensslOpenssl1.0.2b (including)1.0.2b (including)
OpensslOpenssl1.0.2c (including)1.0.2c (including)
OpensslOpenssl1.0.2d (including)1.0.2d (including)
OpensslOpenssl1.0.2e (including)1.0.2e (including)
OpensslOpenssl1.0.2f (including)1.0.2f (including)
OpensslOpenssl1.0.2g (including)1.0.2g (including)
Red Hat Enterprise Linux 6RedHatopenssl-0:1.0.1e-48.el6_8.1*
Red Hat Enterprise Linux 6.7 Extended Update SupportRedHatopenssl-0:1.0.1e-42.el6_7.5*
Red Hat Enterprise Linux 7RedHatopenssl-1:1.0.1e-51.el7_2.5*
Red Hat JBoss Enterprise Application Platform 6.4RedHatopenssl*
Red Hat JBoss Enterprise Web Server 2 for RHEL 6RedHathttpd-0:2.2.26-54.ep6.el6*
Red Hat JBoss Enterprise Web Server 2 for RHEL 6RedHatjbcs-httpd24-0:1-3.jbcs.el6*
Red Hat JBoss Enterprise Web Server 2 for RHEL 6RedHatjbcs-httpd24-openssl-1:1.0.2h-4.jbcs.el6*
Red Hat JBoss Enterprise Web Server 2 for RHEL 6RedHatmod_cluster-0:1.2.13-1.Final_redhat_1.1.ep6.el6*
Red Hat JBoss Enterprise Web Server 2 for RHEL 6RedHatmod_cluster-native-0:1.2.13-3.Final_redhat_2.ep6.el6*
Red Hat JBoss Enterprise Web Server 2 for RHEL 6RedHatmod_jk-0:1.2.41-2.redhat_3.ep6.el6*
Red Hat JBoss Enterprise Web Server 2 for RHEL 6RedHattomcat-native-0:1.1.34-5.redhat_1.ep6.el6*
Red Hat JBoss Enterprise Web Server 2 for RHEL 7RedHathttpd22-0:2.2.26-56.ep6.el7*
Red Hat JBoss Enterprise Web Server 2 for RHEL 7RedHatjbcs-httpd24-0:1-3.jbcs.el7*
Red Hat JBoss Enterprise Web Server 2 for RHEL 7RedHatjbcs-httpd24-openssl-1:1.0.2h-4.jbcs.el7*
Red Hat JBoss Enterprise Web Server 2 for RHEL 7RedHatmod_cluster-0:1.2.13-1.Final_redhat_1.1.ep6.el7*
Red Hat JBoss Enterprise Web Server 2 for RHEL 7RedHatmod_cluster-native-0:1.2.13-3.Final_redhat_2.ep6.el7*
Red Hat JBoss Enterprise Web Server 2 for RHEL 7RedHatmod_jk-0:1.2.41-2.redhat_3.ep6.el7*
Red Hat JBoss Enterprise Web Server 2 for RHEL 7RedHattomcat-native-0:1.1.34-5.redhat_1.ep6.el7*
Red Hat JBoss Web Server 2.1RedHatopenssl*
Text-Only JBCSRedHat*
OpensslUbuntuartful*
OpensslUbuntubionic*
OpensslUbuntucosmic*
OpensslUbuntudevel*
OpensslUbuntudisco*
OpensslUbuntuesm-infra-legacy/trusty*
OpensslUbuntuesm-infra/bionic*
OpensslUbuntuesm-infra/xenial*
OpensslUbuntuprecise*
OpensslUbuntutrusty*
OpensslUbuntutrusty/esm*
OpensslUbuntuupstream*
OpensslUbuntuvivid/stable-phone-overlay*
OpensslUbuntuvivid/ubuntu-core*
OpensslUbuntuwily*
OpensslUbuntuxenial*
OpensslUbuntuyakkety*
OpensslUbuntuzesty*
Openssl098Ubuntuprecise*
Openssl098Ubuntutrusty*

References