ZeroHour

CVE-2016-2107

CVSS 3.1
5.9 medium
EPSS
89%p100
Published
()
Modified
Description

The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obtain sensitive cleartext information via a padding-oracle attack against an AES CBC session. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-0169.

Vendors
redhatopensuseopensslgooglehpnodejsdebiancanonical
Products
enterprise linux desktop, enterprise linux hpc node, enterprise linux hpc node eus, enterprise linux server, enterprise linux server aus, enterprise linux server eus, enterprise linux workstation, leap, opensuse, openssl, android, helion openstack
Weakness
CWE-200, CWE-310
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news