ZeroHour

CVE-2016-2108

CVSS 3.0
9.8 critical
EPSS
78%p100
Published
()
Modified
Description

The ASN.1 implementation in OpenSSL before 1.0.1o and 1.0.2 before 1.0.2c allows remote attackers to execute arbitrary code or cause a denial of service (buffer underflow and memory corruption) via an ANY field in crafted serialized data, aka the "negative zero" issue.

Vendors
redhatopensslgoogle
Products
enterprise linux desktop, enterprise linux hpc node, enterprise linux server, enterprise linux workstation, openssl, enterprise linux hpc node eus, enterprise linux server aus, enterprise linux server eus, android
Weakness
CWE-119
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.