CVE Vulnerabilities

CVE-2016-2179

Published: Sep 16, 2016 | Modified: Apr 12, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
5 MODERATE
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V3
5.3 MODERATE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

The DTLS implementation in OpenSSL before 1.1.0 does not properly restrict the lifetime of queue entries associated with unused out-of-order messages, which allows remote attackers to cause a denial of service (memory consumption) by maintaining many crafted DTLS sessions simultaneously, related to d1_lib.c, statem_dtls.c, statem_lib.c, and statem_srvr.c.

Affected Software

NameVendorStart VersionEnd Version
OpensslOpenssl1.0.1 (including)1.0.1 (including)
OpensslOpenssl1.0.1a (including)1.0.1a (including)
OpensslOpenssl1.0.1b (including)1.0.1b (including)
OpensslOpenssl1.0.1c (including)1.0.1c (including)
OpensslOpenssl1.0.1d (including)1.0.1d (including)
OpensslOpenssl1.0.1e (including)1.0.1e (including)
OpensslOpenssl1.0.1f (including)1.0.1f (including)
OpensslOpenssl1.0.1g (including)1.0.1g (including)
OpensslOpenssl1.0.1h (including)1.0.1h (including)
OpensslOpenssl1.0.1i (including)1.0.1i (including)
OpensslOpenssl1.0.1j (including)1.0.1j (including)
OpensslOpenssl1.0.1k (including)1.0.1k (including)
OpensslOpenssl1.0.1l (including)1.0.1l (including)
OpensslOpenssl1.0.1m (including)1.0.1m (including)
OpensslOpenssl1.0.1n (including)1.0.1n (including)
OpensslOpenssl1.0.1o (including)1.0.1o (including)
OpensslOpenssl1.0.1p (including)1.0.1p (including)
OpensslOpenssl1.0.1q (including)1.0.1q (including)
OpensslOpenssl1.0.1r (including)1.0.1r (including)
OpensslOpenssl1.0.1s (including)1.0.1s (including)
OpensslOpenssl1.0.1t (including)1.0.1t (including)
OpensslOpenssl1.0.2 (including)1.0.2 (including)
OpensslOpenssl1.0.2a (including)1.0.2a (including)
OpensslOpenssl1.0.2b (including)1.0.2b (including)
OpensslOpenssl1.0.2c (including)1.0.2c (including)
OpensslOpenssl1.0.2d (including)1.0.2d (including)
OpensslOpenssl1.0.2e (including)1.0.2e (including)
OpensslOpenssl1.0.2f (including)1.0.2f (including)
OpensslOpenssl1.0.2g (including)1.0.2g (including)
OpensslOpenssl1.0.2h (including)1.0.2h (including)
Red Hat Enterprise Linux 6RedHatopenssl-0:1.0.1e-48.el6_8.3*
Red Hat Enterprise Linux 7RedHatopenssl-1:1.0.1e-51.el7_2.7*
OpensslUbuntuartful*
OpensslUbuntubionic*
OpensslUbuntucosmic*
OpensslUbuntudevel*
OpensslUbuntudisco*
OpensslUbuntuesm-infra-legacy/trusty*
OpensslUbuntuesm-infra/bionic*
OpensslUbuntuesm-infra/xenial*
OpensslUbuntuprecise*
OpensslUbuntutrusty*
OpensslUbuntutrusty/esm*
OpensslUbuntuupstream*
OpensslUbuntuvivid/stable-phone-overlay*
OpensslUbuntuvivid/ubuntu-core*
OpensslUbuntuxenial*
OpensslUbuntuyakkety*
OpensslUbuntuzesty*
Openssl098Ubuntuprecise*
Openssl098Ubuntutrusty*

References