5
CVSSv2

CVE-2016-7052

Published: 26/09/2016 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

crypto/x509/x509_vfy.c in OpenSSL 1.0.2i allows remote malicious users to cause a denial of service (NULL pointer dereference and application crash) by triggering a CRL operation.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

novell suse linux enterprise module for web scripting 12.0

openssl openssl 1.0.2i

nodejs node.js

Vendor Advisories

crypto/x509/x509_vfyc in OpenSSL 102i allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by triggering a CRL operation ...
A bug fix which included a CRL sanity check was added to OpenSSL 110 but was omitted from OpenSSL 102i As a result any attempt to use CRLs in OpenSSL 102i will crash with a null pointer exception The issue was reported to OpenSSL on 22nd September 2016 by Bruce Stephens and Thomas Jakobi ...
On September 22, 2016, the OpenSSL Software Foundation released an advisory that describes 14 vulnerabilities Of these 14 vulnerabilities, the OpenSSL Software Foundation classifies one as “Critical Severity,” one as “Moderate Severity,” and the other 12 as “Low Severity” Subsequently, on September 26, the OpenSSL Software Foundatio ...
SecurityCenter has recently been discovered to have several vulnerabilities Two were reported by external parties while the rest were discovered during internal testing Note that the library vulnerabilities were not fully diagnosed so SecurityCenter may or may not be impacted Tenable opted to upgrade the libraries as it was more efficient Detai ...
Nessus is potentially impacted by several vulnerabilities in OpenSSL (20160926) that were recently disclosed and fixed Note that due to the time involved in doing a full analysis of each issue, Tenable has opted to upgrade the included version of OpenSSL as a precaution, and to save time These vulnerabilities may impact Nessus and include: CVE-2 ...
Tenable's Passive Vulnerability Scanner (PVS) uses third-party libraries to provide certain standardized functionality Four of these libraries were found to contain vulnerabilities and were fixed upstream Those fixes have been integrated despite there being no known exploitation scenarios related to PVS OpenSSL ssl/statem/statemc read_state_ma ...

Exploits

Orion Elite Hidden IP Browser Pro versions 10 through 79 have insecure versions of Tor and OpenSSL included and also suffer from man-in-the-middle vulnerabilities ...

Recent Articles

Patch AGAIN: OpenSSL security fixes now need their own security fixes
The Register • Team Register • 26 Sep 2016

Recursion (n): See recursion

Sysadmins and devs, fresh from a weekend spoiled by last week's OpenSSL emergency patch, have another emergency patch to install. One of last week's fixes, for CVE-2016-6307, created CVE-2016-6309, a dangling pointer security vulnerability. As the fresh advisory states: “The patch applied to address CVE-2016-6307 resulted in an issue where if a message larger than approx 16k is received, then the underlying buffer to store the incoming message is reallocated and moved. “Unfortunately a dangl...