SB2016091933 - Excessive memory allocation in openssl (Alpine package)



SB2016091933 - Excessive memory allocation in openssl (Alpine package)

Published: September 19, 2016

Security Bulletin ID SB2016091933
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Excessive memory allocation (CVE-ID: CVE-2016-2109)

The vulnerability allows a remote user to cause excessive memory allocation on the target system.

The weakness exists during reading ASN.1 data by d2i_CMS_bio() function. A short invalid encoding leads to distribution of large amounts of memory for excessive resources or exhausting memory.

Successful exploitation of the vulnerability may result in excessive memory allocation.

Remediation

Install update from vendor's website.