CVE-2016-2177
OpenSSL through 1.0.2h incorrectly uses pointer arithmetic for heap-buffer boundary checks, which might allow remote attackers to cause a denial of service (integer overflow and application crash) or possibly have unspecified other impact by leveraging unexpected malloc behavior, related to s3_srvr.c, ssl_sess.c, and t1_lib.c.
- Affected products
- Alt Linux, Centos, Cisco Asa, Cisco Ios Xe, Cisco Ios Xr, Cisco Nexus, Cisco Wls, Fortios
- Hp Icewall Mcrp
- = 3.0
- Hp Icewall Sso
- = 10.0
- Hp Icewall Sso Agent Option
- = 10.0
- Fix
- Available
- CVSS 3.0
- 9.8 CRITICAL
- EPSS
- 44.5% (99th percentile)
- Weakness
- CWE-190
- NVD status
- Modified
- Published
- 2016-06-20
CVE-2016-2177 at NVD
2 known exploits for CVE-2016-2177
Proof-of-concept code and exploit modules indexed by Sploitus