Home CVE Database CVE-2016-2182

CVE-2016-2182

Description

An out-of-bounds write vulnerability was found to be caused by not checking errors in BN_bn2dec(). If an oversize BIGNUM is presented to BN_bn2dec() it can cause BN_div_word() to fail and not reduce the value of \'t\' resulting in OOB writes to the bn_data buffer and eventually crashing.

Priority: HIGH
CVSS v3: 9.8
Publish Date: Aug 26, 2016
Related ID: --
CVSS v2: Critical
Modified Date: Aug 26, 2016

Find out more about CVE-2016-2182 from the MITRE-CVE dictionary and NIST NVD


Products Affected

Login may be required to access defects or downloads.

Product Name Status Defect Fixed Downloads
Linux
Wind River Linux LTS 17 Not Vulnerable -- -- --
Wind River Linux 9 Not Vulnerable -- -- --
Wind River Linux 8 Fixed LIN8-4586
8.0.0.9 Wind River Linux 8.0.0.9
Security Advisory - 16 CVE issues of OpenSSL Security Advisory of 22 and 26 Sep 2016
Wind River Linux 8.0.0.10
Wind River Linux 8.0.0.11
Wind River Linux 8.0.0.12
Wind River Linux 8.0.0.13
Wind River Linux 8.0.0.14
Wind River Linux 8.0.0.15
Wind River Linux 8.0.0.16
Wind River Linux 8.0.0.17
Wind River Linux 8.0.0.18
Wind River Linux 8.0.0.19
Wind River Linux 8.0.0.20
Wind River Linux 8.0.0.21
Wind River Linux 8.0.0.22
Wind River Linux 8.0.0.23
Wind River Linux 8.0.0.24
Wind River Linux 8.0.0.25
Wind River Linux 8.0.0.26
Wind River Linux 8.0.0.27
Wind River Linux 8.0.0.28
Wind River Linux 8.0.0.29
Wind River Linux 8.0.0.30
Wind River Linux 8.0.0.31
Wind River Linux 8.0.0.32
Wind River Linux 7 Fixed LIN7-6749
7.0.0.19 Wind River Linux 7.0.0.19
Security Advisory - 16 CVE issues of OpenSSL Security Advisory of 22 and 26 Sep 2016
Wind River Linux 7.0.0.20
Wind River Linux 7.0.0.21
Wind River Linux 7.0.0.22
Wind River Linux 7.0.0.23
Wind River Linux 7.0.0.24
Wind River Linux 7.0.0.25
Wind River Linux 7.0.0.26
Wind River Linux 7.0.0.27
Wind River Linux 7.0.0.28
Wind River Linux 7.0.0.29
Wind River Linux 7.0.0.30
Wind River Linux 7.0.0.31
Wind River Linux LTS 18 Not Vulnerable -- -- --
Wind River Linux LTS 19 Not Vulnerable -- -- --
Wind River Linux CD release Not Vulnerable -- -- --
VxWorks
VxWorks 7 Fixed -- openSSL-1.1.0.0 --
VxWorks 6.9 Fixed -- 6.9.4.9 --
VxWorks 6.8 Vulnerable -- -- --
VxWorks 6.7 Not Vulnerable -- -- --
VxWorks 6.6 Not Vulnerable -- -- --
VxWorks 6.4 Not Vulnerable -- -- --
VxWorks 5.5 Vulnerable -- -- --

Related Products

Product Name Status Defect Fixed Downloads
Linux 7 SCP Not Vulnerable -- -- --
Linux 7 CGP Not Vulnerable -- -- --

Comments

openssl

Live chat
Online