CVE-2016-2107
05.05.2016, 01:59
The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obtain sensitive cleartext information via a padding-oracle attack against an AES CBC session. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-0169.Enginsight
| Vendor | Product | Version |
|---|---|---|
| redhat | enterprise_linux_desktop | 7.0 |
| redhat | enterprise_linux_hpc_node | 7.0 |
| redhat | enterprise_linux_hpc_node_eus | 7.2 |
| redhat | enterprise_linux_server | 7.0 |
| redhat | enterprise_linux_server_aus | 7.2 |
| redhat | enterprise_linux_server_eus | 7.2 |
| redhat | enterprise_linux_workstation | 7.0 |
| opensuse | leap | 42.1 |
| opensuse | opensuse | 13.2 |
| openssl | openssl | 𝑥 ≤ 1.0.1s |
| openssl | openssl | 1.0.2 |
| openssl | openssl | 1.0.2:beta1 |
| openssl | openssl | 1.0.2:beta2 |
| openssl | openssl | 1.0.2:beta3 |
| openssl | openssl | 1.0.2a:a |
| openssl | openssl | 1.0.2b:b |
| openssl | openssl | 1.0.2c:c |
| openssl | openssl | 1.0.2d:d |
| openssl | openssl | 1.0.2e:e |
| openssl | openssl | 1.0.2f:f |
| openssl | openssl | 1.0.2g:g |
| android | 4.0 | |
| android | 4.0.1 | |
| android | 4.0.2 | |
| android | 4.0.3 | |
| android | 4.0.4 | |
| android | 4.1 | |
| android | 4.1.2 | |
| android | 4.2 | |
| android | 4.2.1 | |
| android | 4.2.2 | |
| android | 4.3 | |
| android | 4.3.1 | |
| android | 4.4 | |
| android | 4.4.1 | |
| android | 4.4.2 | |
| android | 4.4.3 | |
| android | 5.0 | |
| android | 5.0.1 | |
| android | 5.1 | |
| android | 5.1.0 | |
| hp | helion_openstack | 2.0.0 |
| hp | helion_openstack | 2.1.0 |
| hp | helion_openstack | 2.1.2 |
| hp | helion_openstack | 2.1.4 |
| redhat | enterprise_linux_desktop | 6.0 |
| redhat | enterprise_linux_hpc_node | 6.0 |
| redhat | enterprise_linux_server | 6.0 |
| redhat | enterprise_linux_workstation | 6.0 |
| nodejs | node.js | 0.10.0 ≤ 𝑥 < 0.10.45 |
| nodejs | node.js | 0.12.0 ≤ 𝑥 < 0.12.14 |
| nodejs | node.js | 4.0.0 ≤ 𝑥 ≤ 4.1.2 |
| nodejs | node.js | 4.2.0 ≤ 𝑥 < 4.4.4 |
| nodejs | node.js | 5.0.0 ≤ 𝑥 < 5.11.1 |
| nodejs | node.js | 6.0.0 |
| debian | debian_linux | 8.0 |
| canonical | ubuntu_linux | 12.04 |
| canonical | ubuntu_linux | 14.04 |
| canonical | ubuntu_linux | 15.10 |
| canonical | ubuntu_linux | 16.04 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| openssl |
| ||||||||||||||||||||
| openssl098 |
|
Common Weakness Enumeration