Wind River Support Network

HomeDefectsLIN5-21426
Fixed

LIN5-21426 : Security Advisory - OpenSSL - CVE-2016-2176

Created: May 3, 2016    Updated: May 29, 2018
Resolved Date: May 4, 2016
Found In Version: 5.0.1.35
Fix Version: 5.0.1.36
Severity: Standard
Applicable for: Wind River Linux 5
Component/s: Userspace

Description

EBCDIC overread (CVE-2016-2176)
===============================

Severity: Low

ASN1 Strings that are over 1024 bytes can cause an overread in applications
using the X509_NAME_oneline() function on EBCDIC systems. This could result in
arbitrary stack data being returned in the buffer.

This issue was reported to OpenSSL on 5th March 2016 by Guido Vranken. The
fix was developed by Matt Caswell of the OpenSSL development team.

Other Downloads


Live chat
Online