OpenSSL through 1.0.2h incorrectly uses pointer arithmetic for heap-buffer boundary checks, which might allow remote attackers to cause a denial of service (integer overflow and application crash) or possibly have unspecified other impact by leveraging unexpected malloc behavior, related to s3_srvr.c, ssl_sess.c, and t1_lib.c.
The product performs a calculation that can produce an integer overflow or wraparound, when the logic assumes that the resulting value will always be larger than the original value. This can introduce other weaknesses when the calculation is used for resource management or execution control.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Icewall_mcrp | Hp | 3.0 (including) | 3.0 (including) |
Icewall_sso | Hp | 10.0 (including) | 10.0 (including) |
Icewall_sso_agent_option | Hp | 10.0 (including) | 10.0 (including) |
Openssl | Ubuntu | artful | * |
Openssl | Ubuntu | bionic | * |
Openssl | Ubuntu | cosmic | * |
Openssl | Ubuntu | devel | * |
Openssl | Ubuntu | disco | * |
Openssl | Ubuntu | precise | * |
Openssl | Ubuntu | trusty | * |
Openssl | Ubuntu | upstream | * |
Openssl | Ubuntu | vivid/stable-phone-overlay | * |
Openssl | Ubuntu | vivid/ubuntu-core | * |
Openssl | Ubuntu | wily | * |
Openssl | Ubuntu | xenial | * |
Openssl | Ubuntu | yakkety | * |
Openssl | Ubuntu | zesty | * |
Openssl098 | Ubuntu | precise | * |
Openssl098 | Ubuntu | trusty | * |
JBoss Core Services on RHEL 6 | RedHat | jbcs-httpd24-httpd-0:2.4.23-102.jbcs.el6 | * |
JBoss Core Services on RHEL 6 | RedHat | jbcs-httpd24-mod_auth_kerb-0:5.4-35.jbcs.el6 | * |
JBoss Core Services on RHEL 6 | RedHat | jbcs-httpd24-mod_bmx-0:0.9.6-14.GA.jbcs.el6 | * |
JBoss Core Services on RHEL 6 | RedHat | jbcs-httpd24-mod_cluster-native-0:1.3.5-13.Final_redhat_1.jbcs.el6 | * |
JBoss Core Services on RHEL 6 | RedHat | jbcs-httpd24-mod_jk-0:1.2.41-14.redhat_1.jbcs.el6 | * |
JBoss Core Services on RHEL 6 | RedHat | jbcs-httpd24-mod_rt-0:2.4.1-16.GA.jbcs.el6 | * |
JBoss Core Services on RHEL 6 | RedHat | jbcs-httpd24-mod_security-0:2.9.1-18.GA.jbcs.el6 | * |
JBoss Core Services on RHEL 6 | RedHat | jbcs-httpd24-nghttp2-0:1.12.0-9.jbcs.el6 | * |
JBoss Core Services on RHEL 6 | RedHat | jbcs-httpd24-openssl-1:1.0.2h-12.jbcs.el6 | * |
JBoss Core Services on RHEL 7 | RedHat | jbcs-httpd24-httpd-0:2.4.23-102.jbcs.el7 | * |
JBoss Core Services on RHEL 7 | RedHat | jbcs-httpd24-mod_auth_kerb-0:5.4-35.jbcs.el7 | * |
JBoss Core Services on RHEL 7 | RedHat | jbcs-httpd24-mod_bmx-0:0.9.6-14.GA.jbcs.el7 | * |
JBoss Core Services on RHEL 7 | RedHat | jbcs-httpd24-mod_cluster-native-0:1.3.5-13.Final_redhat_1.jbcs.el7 | * |
JBoss Core Services on RHEL 7 | RedHat | jbcs-httpd24-mod_jk-0:1.2.41-14.redhat_1.jbcs.el7 | * |
JBoss Core Services on RHEL 7 | RedHat | jbcs-httpd24-mod_rt-0:2.4.1-16.GA.jbcs.el7 | * |
JBoss Core Services on RHEL 7 | RedHat | jbcs-httpd24-mod_security-0:2.9.1-18.GA.jbcs.el7 | * |
JBoss Core Services on RHEL 7 | RedHat | jbcs-httpd24-nghttp2-0:1.12.0-9.jbcs.el7 | * |
JBoss Core Services on RHEL 7 | RedHat | jbcs-httpd24-openssl-1:1.0.2h-12.jbcs.el7 | * |
Red Hat Enterprise Linux 6 | RedHat | openssl-0:1.0.1e-48.el6_8.3 | * |
Red Hat Enterprise Linux 7 | RedHat | openssl-1:1.0.1e-51.el7_2.7 | * |
Red Hat JBoss Core Services 1 | RedHat | * | |
Red Hat JBoss Enterprise Application Platform 6.4 | RedHat | openssl | * |
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 | RedHat | jbcs-httpd24-openssl-1:1.0.2h-13.jbcs.el6 | * |
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7 | RedHat | jbcs-httpd24-openssl-1:1.0.2h-13.jbcs.el7 | * |