CVE-2016-2109
The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in the ASN.1 BIO implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (memory consumption) via a short invalid encoding.
- Affected products
- Alt Linux, Centos, Cisco Asa, Cisco Nexus, Cisco Wls, Freebsd, Huawei Vrp, Ibm Aix
- Openssl
- ≤ 1.0.1s, 1.0.2, 1.0.2a, 1.0.2b, 1.0.2c, 1.0.2d, 1.0.2e, 1.0.2f, 1.0.2g
- Fix
- Available
- CVSS 2.0
- 7.8 HIGH
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 29.2% (98th percentile)
- Weakness
- CWE-399
- NVD status
- Modified
- Published
- 2016-05-05
CVE-2016-2109 at NVD
1 known exploit for CVE-2016-2109
Proof-of-concept code and exploit modules indexed by Sploitus