CVE-2016-8610

Published Nov 13, 2017

Last updated a month ago

Overview

Description
A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote attacker could use this flaw to make a TLS/SSL server consume an excessive amount of CPU and fail to accept connections from other clients.
Source
secalert@redhat.com
NVD status
Modified
Products
openssl, debian_linux, enterprise_linux_desktop, enterprise_linux_server, enterprise_linux_server_aus, enterprise_linux_server_eus, enterprise_linux_server_tus, enterprise_linux_workstation, jboss_enterprise_application_platform, cn1610_firmware, clustered_data_ontap_antivirus_connector, data_ontap, data_ontap_edge, e-series_santricity_os_controller, host_agent, oncommand_balance, oncommand_unified_manager, oncommand_workflow_automation, ontap_select_deploy, service_processor, smi-s_provider, snapcenter_server, snapdrive, storagegrid, storagegrid_webscale, clustered_data_ontap, pan-os, adaptive_access_manager, application_testing_suite, communications_analytics, communications_ip_service_activator, core_rdbms, enterprise_manager_ops_center, goldengate_application_adapters, jd_edwards_enterpriseone_tools, peoplesoft_enterprise_peopletools, retail_predictive_application_server, timesten_in-memory_database, weblogic_server, m10-1_firmware, m10-4_firmware, m10-4s_firmware, m12-1_firmware, m12-2_firmware, m12-2s_firmware

Risk scores

CVSS 3.1

Type
Primary
Base score
7.5
Impact score
3.6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity
HIGH

CVSS 2.0

Type
Primary
Base score
5
Impact score
2.9
Exploitability score
10
Vector string
AV:N/AC:L/Au:N/C:N/I:N/A:P

Weaknesses

secalert@redhat.com
CWE-400
nvd@nist.gov
CWE-400

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.