CVE-2016-2106
05.05.2016, 01:59
Integer overflow in the EVP_EncryptUpdate function in crypto/evp/evp_enc.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (heap memory corruption) via a large amount of data.Enginsight
Vendor | Product | Version |
---|---|---|
openssl | openssl | 𝑥 ≤ 1.0.1s |
openssl | openssl | 1.0.2 |
openssl | openssl | 1.0.2:beta1 |
openssl | openssl | 1.0.2:beta2 |
openssl | openssl | 1.0.2:beta3 |
openssl | openssl | 1.0.2a:a |
openssl | openssl | 1.0.2b:b |
openssl | openssl | 1.0.2c:c |
openssl | openssl | 1.0.2d:d |
openssl | openssl | 1.0.2e:e |
openssl | openssl | 1.0.2f:f |
openssl | openssl | 1.0.2g:g |
redhat | enterprise_linux_desktop | 7.0 |
redhat | enterprise_linux_hpc_node | 7.0 |
redhat | enterprise_linux_hpc_node_eus | 7.2 |
redhat | enterprise_linux_server | 7.0 |
redhat | enterprise_linux_server_aus | 7.2 |
redhat | enterprise_linux_server_eus | 7.2 |
redhat | enterprise_linux_workstation | 7.0 |
redhat | enterprise_linux_desktop | 6.0 |
redhat | enterprise_linux_hpc_node | 6.0 |
redhat | enterprise_linux_server | 6.0 |
redhat | enterprise_linux_workstation | 6.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
openssl |
| ||||||||||||||||||||
openssl098 |
|
Common Weakness Enumeration