CVE-2016-8610
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote attacker could use this flaw to make a TLS/SSL server consume an excessive amount of CPU and fail to accept connections from other clients.
Affected (78)
Products: Openssl: Openssl · Debian: Debian Linux · Redhat: Enterprise Linux Desktop, Enterprise Linux Server, Enterprise Linux Server Aus, Enterprise Linux Server Eus, Enterprise Linux Server Tus, Enterprise Linux Workstation, Jboss Enterprise Application Platform · +4 more
Show all products
Openssl: Openssl · Debian: Debian Linux · Redhat: Enterprise Linux Desktop, Enterprise Linux Server, Enterprise Linux Server Aus, Enterprise Linux Server Eus, Enterprise Linux Server Tus, Enterprise Linux Workstation, Jboss Enterprise Application Platform · Netapp: Cn1610 Firmware, Clustered Data Ontap, Clustered Data Ontap Antivirus Connector, Data Ontap, Data Ontap Edge, E Series Santricity Os Controller, Host Agent, Oncommand Balance, Oncommand Unified Manager, Oncommand Workflow Automation, Ontap Select Deploy, Service Processor, Smi S Provider, Snapcenter Server, Snapdrive, Storagegrid, Storagegrid Webscale · Paloaltonetworks: Pan Os · Oracle: Adaptive Access Manager, Application Testing Suite, Communications Analytics, Communications Ip Service Activator, Core Rdbms, Enterprise Manager Ops Center, Goldengate Application Adapters, Jd Edwards Enterpriseone Tools, Peoplesoft Enterprise Peopletools, Retail Predictive Application Server, Timesten In Memory Database, Weblogic Server · Fujitsu: M10 1 Firmware, M10 4 Firmware, M10 4s Firmware, M12 1 Firmware, M12 2 Firmware, M12 2s Firmware
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 8.0 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 6.0 | |
| Version 6.0 | |
| Version 7.3 | |
| Version 7.3 | |
| Version 7.3 | |
| Version 6.0 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 6.0.0 |
| Running on/with | Platform Versions |
|---|---|
Redhat Enterprise Linux | Version 6.0 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp Cn1610 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| From 11.0 to 11.40 | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 6.1.17 |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.1.2.3.0 | |
| Version 13.3.0.1 | |
| Version 12.1.1 | |
| Version 7.3.4 | |
| Version 11.2.0.4 | |
| Version 12.3.3 | |
| Version 12.3.2.1.0 | |
| Version 9.2 | |
| Version 8.56 | |
| Version 15.0.3 | |
| Before 18.1.4.1.0 | |
| Version 10.3.6.0.0 |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before xcp2361 |
| Running on/with | Platform Versions |
|---|---|
Fujitsu M10 1 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before xcp2361 |
| Running on/with | Platform Versions |
|---|---|
Fujitsu M10 4 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before xcp2361 |
| Running on/with | Platform Versions |
|---|---|
Fujitsu M10 4s | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before xcp2361 |
| Running on/with | Platform Versions |
|---|---|
Fujitsu M12 1 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before xcp2361 |
| Running on/with | Platform Versions |
|---|---|
Fujitsu M12 2 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before xcp2361 |
| Running on/with | Platform Versions |
|---|---|
Fujitsu M12 2s | All versions |
References (56)
Source: secalert@redhat.com
Issue TrackingPatchThird Party Advisory
Source: secalert@redhat.com
Broken Link
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
PatchThird Party Advisory
Source: secalert@redhat.com
PatchThird Party Advisory
Source: secalert@redhat.com
PatchThird Party Advisory
Source: secalert@redhat.com
PatchThird Party Advisory
Source: secalert@redhat.com
PatchThird Party Advisory
Source: secalert@redhat.com
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Timeline
No history available yet.