CVE-2016-6304
Multiple memory leaks in t1_lib.c in OpenSSL before 1.0.1u, 1.0.2 before 1.0.2i, and 1.1.0 before 1.1.0a allow remote attackers to cause a denial of service (memory consumption) via large OCSP Status Request extensions.
- Affected products
- Alt Linux, Centos, Cisco Asa, Cisco Nexus, Cisco Wls, Fortios, Freebsd, Huawei Vrp
- Openssl
- = 1.0.2, 1.0.2a, 1.0.2b, 1.0.2c, 1.0.2d, 1.0.2e, 1.0.2f, 1.0.2h
- Fix
- Available
- CVSS 2.0
- 7.8 HIGH
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 63.0% (99th percentile)
- Weakness
- CWE-401
- NVD status
- Modified
- Published
- 2016-09-26
CVE-2016-6304 at NVD
3 known exploits for CVE-2016-6304
Proof-of-concept code and exploit modules indexed by Sploitus