OpenSSL through 1.0.2h incorrectly uses pointer arithmetic for heap-buffer boundary checks, which might allow remote attackers to cause a denial of service (integer overflow and application crash) or possibly have unspecified other impact by leveraging unexpected malloc behavior, related to s3_srvr.c, ssl_sess.c, and t1_lib.c.
The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Icewall_mcrp | Hp | 3.0 (including) | 3.0 (including) |
Icewall_sso | Hp | 10.0 (including) | 10.0 (including) |
Icewall_sso_agent_option | Hp | 10.0 (including) | 10.0 (including) |
JBoss Core Services on RHEL 6 | RedHat | jbcs-httpd24-httpd-0:2.4.23-102.jbcs.el6 | * |
JBoss Core Services on RHEL 6 | RedHat | jbcs-httpd24-mod_auth_kerb-0:5.4-35.jbcs.el6 | * |
JBoss Core Services on RHEL 6 | RedHat | jbcs-httpd24-mod_bmx-0:0.9.6-14.GA.jbcs.el6 | * |
JBoss Core Services on RHEL 6 | RedHat | jbcs-httpd24-mod_cluster-native-0:1.3.5-13.Final_redhat_1.jbcs.el6 | * |
JBoss Core Services on RHEL 6 | RedHat | jbcs-httpd24-mod_jk-0:1.2.41-14.redhat_1.jbcs.el6 | * |
JBoss Core Services on RHEL 6 | RedHat | jbcs-httpd24-mod_rt-0:2.4.1-16.GA.jbcs.el6 | * |
JBoss Core Services on RHEL 6 | RedHat | jbcs-httpd24-mod_security-0:2.9.1-18.GA.jbcs.el6 | * |
JBoss Core Services on RHEL 6 | RedHat | jbcs-httpd24-nghttp2-0:1.12.0-9.jbcs.el6 | * |
JBoss Core Services on RHEL 6 | RedHat | jbcs-httpd24-openssl-1:1.0.2h-12.jbcs.el6 | * |
JBoss Core Services on RHEL 7 | RedHat | jbcs-httpd24-httpd-0:2.4.23-102.jbcs.el7 | * |
JBoss Core Services on RHEL 7 | RedHat | jbcs-httpd24-mod_auth_kerb-0:5.4-35.jbcs.el7 | * |
JBoss Core Services on RHEL 7 | RedHat | jbcs-httpd24-mod_bmx-0:0.9.6-14.GA.jbcs.el7 | * |
JBoss Core Services on RHEL 7 | RedHat | jbcs-httpd24-mod_cluster-native-0:1.3.5-13.Final_redhat_1.jbcs.el7 | * |
JBoss Core Services on RHEL 7 | RedHat | jbcs-httpd24-mod_jk-0:1.2.41-14.redhat_1.jbcs.el7 | * |
JBoss Core Services on RHEL 7 | RedHat | jbcs-httpd24-mod_rt-0:2.4.1-16.GA.jbcs.el7 | * |
JBoss Core Services on RHEL 7 | RedHat | jbcs-httpd24-mod_security-0:2.9.1-18.GA.jbcs.el7 | * |
JBoss Core Services on RHEL 7 | RedHat | jbcs-httpd24-nghttp2-0:1.12.0-9.jbcs.el7 | * |
JBoss Core Services on RHEL 7 | RedHat | jbcs-httpd24-openssl-1:1.0.2h-12.jbcs.el7 | * |
Red Hat Enterprise Linux 6 | RedHat | openssl-0:1.0.1e-48.el6_8.3 | * |
Red Hat Enterprise Linux 7 | RedHat | openssl-1:1.0.1e-51.el7_2.7 | * |
Red Hat JBoss Enterprise Application Platform 6.4 | RedHat | openssl | * |
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 | RedHat | jbcs-httpd24-openssl-1:1.0.2h-13.jbcs.el6 | * |
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7 | RedHat | jbcs-httpd24-openssl-1:1.0.2h-13.jbcs.el7 | * |
Text-Only JBCS | RedHat | * | |
Openssl | Ubuntu | artful | * |
Openssl | Ubuntu | bionic | * |
Openssl | Ubuntu | cosmic | * |
Openssl | Ubuntu | devel | * |
Openssl | Ubuntu | disco | * |
Openssl | Ubuntu | esm-infra-legacy/trusty | * |
Openssl | Ubuntu | esm-infra/bionic | * |
Openssl | Ubuntu | esm-infra/xenial | * |
Openssl | Ubuntu | precise | * |
Openssl | Ubuntu | trusty | * |
Openssl | Ubuntu | trusty/esm | * |
Openssl | Ubuntu | upstream | * |
Openssl | Ubuntu | vivid/stable-phone-overlay | * |
Openssl | Ubuntu | vivid/ubuntu-core | * |
Openssl | Ubuntu | wily | * |
Openssl | Ubuntu | xenial | * |
Openssl | Ubuntu | yakkety | * |
Openssl | Ubuntu | zesty | * |
Openssl098 | Ubuntu | precise | * |
Openssl098 | Ubuntu | trusty | * |