ZeroHour

CVE-2016-2182

CVSS 3.0
9.8 critical
EPSS
44%p99
Published
()
Modified
Description

The BN_bn2dec function in crypto/bn/bn_print.c in OpenSSL before 1.1.0 does not properly validate division results, which allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or possibly have unspecified other impact via unknown vectors.

Vendors
hpopenssloracle
Products
icewall federation agent, icewall mcrp, icewall sso, icewall sso agent option, openssl, linux
Weakness
CWE-787
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.