OpenSSL: Double-free in DSA code
Published Mar 3, 2016
9.8
CRITICALCVSS 3.0
EPSS 26.33%
Description
Double free vulnerability in the dsa_priv_decode function in crypto/dsa/dsa_ameth.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a malformed DSA private key.
Affected products
No data.
Configuration 1
Configuration 2
- 1.0.1
- 1.0.1
- 1.0.1
- 1.0.1
- 1.0.1a
- 1.0.1b
- 1.0.1c
- 1.0.1d
- 1.0.1e
- 1.0.1f
- 1.0.1g
- 1.0.1h
- 1.0.1i
- 1.0.1j
- 1.0.1k
- 1.0.1l
- 1.0.1m
- 1.0.1n
- 1.0.1o
- 1.0.1p
- 1.0.1q
- 1.0.1r
- 1.0.2
- 1.0.2
- 1.0.2
- 1.0.2
- 1.0.2a
- 1.0.2b
- 1.0.2c
- 1.0.2d
- 1.0.2e
- 1.0.2f
Configuration 3
- 4.0
- 4.0.1
- 4.0.2
- 4.0.3
- 4.0.4
- 4.1
- 4.1.2
- 4.2
- 4.2.1
- 4.2.2
- 4.3
- 4.3.1
- 4.4
- 4.4.1
- 4.4.2
- 4.4.3
- 5.0
- 5.0.1
- 5.1
- 5.1.0
- 6.0
- 6.0.1
Configuration 4
- 12.04
- 14.04
- 15.10
Configuration 5
- 7.0
- 8.0
No data.
RHEV 3.X Hypervisor and Agents for RHEL-6
rhev-hypervisor7-0:7.2-20160302.1.el6ev
Fixed · RHSA-2016:0379
RHEV 3.X Hypervisor and Agents for RHEL-7
rhev-hypervisor7-0:7.2-20160302.1.el7ev
Fixed · RHSA-2016:0379
Red Hat Enterprise Linux 6
openssl-0:1.0.1e-42.el6_7.4
Fixed · RHSA-2016:0301
Red Hat Enterprise Linux 6 Supplementary
java-1.8.0-ibm-1:1.8.0.5.20-1jpp.1.el6_10
Fixed · RHSA-2018:2575
Red Hat Enterprise Linux 7
openssl-1:1.0.1e-51.el7_2.4
Fixed · RHSA-2016:0301
Red Hat Enterprise Linux 7 Supplementary
java-1.8.0-ibm-1:1.8.0.5.20-1jpp.1.el7
Fixed · RHSA-2018:2568
Red Hat JBoss Core Services
n/a
Fixed · RHSA-2016:2957
Red Hat Satellite 5.8
java-1.8.0-ibm-1:1.8.0.5.20-1jpp.1.el6_10
Fixed · RHSA-2018:2713
Red Hat Enterprise Linux 5
openssl
Not affected
Red Hat Enterprise Linux 5
openssl097a
Not affected
Red Hat Enterprise Linux 6
guest-images
Affected
Red Hat Enterprise Linux 6
openssl098e
Not affected
Red Hat Enterprise Linux 7
openssl098e
Not affected
Red Hat Enterprise Linux 7
rhel-guest-image
Affected
Red Hat JBoss Enterprise Application Platform 6
openssl
Not affected
Red Hat JBoss Enterprise Web Server 2
openssl
Not affected
Red Hat JBoss Enterprise Web Server 3
openssl
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| RHEV 3.X Hypervisor and Agents for RHEL-6 | rhev-hypervisor7-0:7.2-20160302.1.el6ev | Fixed | RHSA-2016:0379 |
| RHEV 3.X Hypervisor and Agents for RHEL-7 | rhev-hypervisor7-0:7.2-20160302.1.el7ev | Fixed | RHSA-2016:0379 |
| Red Hat Enterprise Linux 6 | openssl-0:1.0.1e-42.el6_7.4 | Fixed | RHSA-2016:0301 |
| Red Hat Enterprise Linux 6 Supplementary | java-1.8.0-ibm-1:1.8.0.5.20-1jpp.1.el6_10 | Fixed | RHSA-2018:2575 |
| Red Hat Enterprise Linux 7 | openssl-1:1.0.1e-51.el7_2.4 | Fixed | RHSA-2016:0301 |
| Red Hat Enterprise Linux 7 Supplementary | java-1.8.0-ibm-1:1.8.0.5.20-1jpp.1.el7 | Fixed | RHSA-2018:2568 |
| Red Hat JBoss Core Services | n/a | Fixed | RHSA-2016:2957 |
| Red Hat Satellite 5.8 | java-1.8.0-ibm-1:1.8.0.5.20-1jpp.1.el6_10 | Fixed | RHSA-2018:2713 |
| Red Hat Enterprise Linux 5 | openssl | Not affected | n/a |
| Red Hat Enterprise Linux 5 | openssl097a | Not affected | n/a |
| Red Hat Enterprise Linux 6 | guest-images | Affected | n/a |
| Red Hat Enterprise Linux 6 | openssl098e | Not affected | n/a |
| Red Hat Enterprise Linux 7 | openssl098e | Not affected | n/a |
| Red Hat Enterprise Linux 7 | rhel-guest-image | Affected | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | openssl | Not affected | n/a |
| Red Hat JBoss Enterprise Web Server 2 | openssl | Not affected | n/a |
| Red Hat JBoss Enterprise Web Server 3 | openssl | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AV:N/AC:L/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (71 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 26.33% (0.26335) | 97.95th | v5 (v2026.06.15) |
| Jun 15, 2026 | 26.33% (0.26335) | 97.74th | v5 (v2026.06.15) |
| Jun 10, 2026 | 20.19% (0.20189) | 95.64th | v4 (v2025.03.14) |
| May 12, 2026 | 21.83% (0.21835) | 95.80th | v4 (v2025.03.14) |
| Apr 21, 2026 | 20.66% (0.20656) | 95.60th | v4 (v2025.03.14) |
| Apr 11, 2026 | 21.83% (0.21835) | 95.76th | v4 (v2025.03.14) |
| Mar 4, 2026 | 24.28% (0.24282) | 95.98th | v4 (v2025.03.14) |
| Mar 1, 2026 | 11.78% (0.11782) | 93.59th | v4 (v2025.03.14) |
| Feb 21, 2026 | 24.82% (0.24819) | 96.03th | v4 (v2025.03.14) |
| Feb 4, 2026 | 23.08% (0.23078) | 95.78th | v4 (v2025.03.14) |
| Feb 1, 2026 | 9.72% (0.09720) | 92.76th | v4 (v2025.03.14) |
| Jan 17, 2026 | 23.08% (0.23078) | 95.74th | v4 (v2025.03.14) |
| Jan 4, 2026 | 20.66% (0.20656) | 95.39th | v4 (v2025.03.14) |
| Jan 1, 2026 | 9.72% (0.09720) | 92.72th | v4 (v2025.03.14) |
| Dec 28, 2025 | 20.66% (0.20656) | 95.40th | v4 (v2025.03.14) |
| Dec 27, 2025 | 33.83% (0.33825) | 96.82th | v4 (v2025.03.14) |
| Dec 11, 2025 | 20.66% (0.20656) | 95.38th | v4 (v2025.03.14) |
| Dec 4, 2025 | 21.83% (0.21835) | 95.54th | v4 (v2025.03.14) |
| Dec 1, 2025 | 10.38% (0.10378) | 92.97th | v4 (v2025.03.14) |
| Nov 25, 2025 | 21.83% (0.21835) | 95.53th | v4 (v2025.03.14) |
| Nov 4, 2025 | 20.66% (0.20656) | 95.34th | v4 (v2025.03.14) |
| Nov 1, 2025 | 9.72% (0.09720) | 92.62th | v4 (v2025.03.14) |
| Oct 28, 2025 | 20.66% (0.20656) | 95.33th | v4 (v2025.03.14) |
| Oct 27, 2025 | 33.83% (0.33825) | 96.76th | v4 (v2025.03.14) |
| Oct 13, 2025 | 20.66% (0.20656) | 95.30th | v4 (v2025.03.14) |
| Oct 4, 2025 | 21.83% (0.21835) | 95.56th | v4 (v2025.03.14) |
| Oct 1, 2025 | 10.38% (0.10378) | 92.97th | v4 (v2025.03.14) |
| Sep 22, 2025 | 35.36% (0.35356) | 96.94th | v4 (v2025.03.14) |
| Sep 5, 2025 | 39.01% (0.39014) | 97.18th | v4 (v2025.03.14) |
| Sep 1, 2025 | 21.56% (0.21564) | 95.55th | v4 (v2025.03.14) |
| Aug 24, 2025 | 38.43% (0.38432) | 97.13th | v4 (v2025.03.14) |
| Aug 21, 2025 | 44.33% (0.44334) | 97.46th | v4 (v2025.03.14) |
| Aug 4, 2025 | 38.43% (0.38432) | 97.11th | v4 (v2025.03.14) |
| Aug 1, 2025 | 21.28% (0.21282) | 95.48th | v4 (v2025.03.14) |
| Jul 30, 2025 | 38.64% (0.38637) | 97.11th | v4 (v2025.03.14) |
| Jul 9, 2025 | 24.45% (0.24450) | 95.85th | v4 (v2025.03.14) |
| Jul 5, 2025 | 21.99% (0.21992) | 95.49th | v4 (v2025.03.14) |
| Jul 1, 2025 | 10.47% (0.10466) | 92.92th | v4 (v2025.03.14) |
| Jun 23, 2025 | 21.99% (0.21992) | 95.47th | v4 (v2025.03.14) |
| Jun 4, 2025 | 20.66% (0.20656) | 95.26th | v4 (v2025.03.14) |
| Jun 1, 2025 | 9.72% (0.09720) | 92.55th | v4 (v2025.03.14) |
| May 5, 2025 | 21.99% (0.21992) | 95.40th | v4 (v2025.03.14) |
| May 1, 2025 | 9.72% (0.09720) | 92.52th | v4 (v2025.03.14) |
| Apr 27, 2025 | 20.66% (0.20656) | 95.20th | v4 (v2025.03.14) |
| Apr 19, 2025 | 23.08% (0.23078) | 95.54th | v4 (v2025.03.14) |
| Apr 18, 2025 | 9.72% (0.09720) | 92.46th | v4 (v2025.03.14) |
| Apr 10, 2025 | 23.08% (0.23078) | 95.46th | v4 (v2025.03.14) |
| Mar 31, 2025 | 21.09% (0.21085) | 95.16th | v4 (v2025.03.14) |
| Mar 30, 2025 | 19.35% (0.19352) | 94.90th | v4 (v2025.03.14) |
| Mar 29, 2025 | 75.43% (0.75427) | 98.55th | v4 (v2025.03.14) |
| Mar 28, 2025 | 19.35% (0.19352) | 94.90th | v4 (v2025.03.14) |
| Mar 27, 2025 | 75.43% (0.75427) | 98.80th | v4 (v2025.03.14) |
| Mar 26, 2025 | 44.67% (0.44675) | 97.27th | v4 (v2025.03.14) |
| Mar 24, 2025 | 51.17% (0.51168) | 97.65th | v4 (v2025.03.14) |
| Mar 23, 2025 | 41.63% (0.41626) | 97.01th | v4 (v2025.03.14) |
| Mar 20, 2025 | 51.17% (0.51168) | 97.67th | v4 (v2025.03.14) |
| Mar 19, 2025 | 75.44% (0.75445) | 98.82th | v4 (v2025.03.14) |
| Mar 18, 2025 | 51.17% (0.51168) | 97.65th | v4 (v2025.03.14) |
| Mar 17, 2025 | 41.63% (0.41626) | 97.10th | v4 (v2025.03.14) |
| Feb 8, 2025 | 6.31% (0.06306) | 93.63th | v3 (v2023.03.01) |
| Dec 17, 2024 | 8.65% (0.08646) | 94.49th | v3 (v2023.03.01) |
| Sep 26, 2024 | 6.04% (0.06036) | 93.65th | v3 (v2023.03.01) |
| Nov 11, 2023 | 3.99% (0.03992) | 91.05th | v3 (v2023.03.01) |
| Nov 8, 2023 | 2.80% (0.02796) | 89.52th | v3 (v2023.03.01) |
| Oct 20, 2023 | 3.86% (0.03857) | 90.88th | v3 (v2023.03.01) |
| Jun 4, 2023 | 3.99% (0.03990) | 90.77th | v3 (v2023.03.01) |
| Mar 16, 2023 | 3.31% (0.03308) | 89.80th | v3 (v2023.03.01) |
| Mar 7, 2023 | 2.83% (0.02830) | 89.08th | v3 (v2023.03.01) |
| Mar 6, 2023 | 7.56% (0.07559) | 92.87th | v2 (v2022.01.01) |
| Apr 1, 2022 | 7.56% (0.07559) | 92.17th | v2 (v2022.01.01) |
| Feb 4, 2022 | 7.56% (0.07559) | 81.11th | v2 (v2022.01.01) |
No CWE recorded.
References (61)
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10759 Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2016-March/178358.html vendor-advisoryMailing ListThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2016-March/178817.html vendor-advisoryMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00001.html vendor-advisoryMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00002.html vendor-advisoryMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00003.html vendor-advisoryMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00004.html vendor-advisoryMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00005.html vendor-advisoryMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00006.html vendor-advisoryMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00007.html vendor-advisoryMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00009.html vendor-advisoryMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00010.html vendor-advisoryMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00038.html vendor-advisoryMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00053.html vendor-advisoryMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00019.html vendor-advisoryMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=145889460330120&w=2 vendor-advisoryMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=145983526810210&w=2 vendor-advisoryMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=146108058503441&w=2 vendor-advisoryMailing ListThird Party Advisory
- http://openssl.org/news/secadv/20160301.txt Vendor Advisory
- http://rhn.redhat.com/errata/RHSA-2016-2957.html vendor-advisoryThird Party Advisory
- http://source.android.com/security/bulletin/2016-05-01.html Third Party Advisory
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160302-openssl vendor-advisoryThird Party Advisory
- http://www.debian.org/security/2016/dsa-3500 vendor-advisoryThird Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html PatchVendor Advisory
- http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html PatchVendor Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html Vendor Advisory
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html Vendor Advisory
- http://www.securityfocus.com/bid/83754 vdb-entryThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/91787 vdb-entryThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1035133 vdb-entryThird Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/USN-2914-1 vendor-advisoryThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2568 vendor-advisoryThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2575 vendor-advisoryThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2713 vendor-advisoryThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2016-0705 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1310596 Issue Tracking
- https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdf
- https://git.openssl.org/?p=openssl.git%3Ba=commit%3Bh=6c88c71b4e4825c7bc0489306d062d017634eb88
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03741en_us Third Party Advisory
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05052990 Third Party Advisory
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05068681 Third Party Advisory
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05086877 Third Party Advisory
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05111017 Third Party Advisory
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05126404 Third Party Advisory
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05131085 Third Party Advisory
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05135617 Third Party Advisory
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05141441 Third Party Advisory
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05150736 Third Party Advisory
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05150800 Third Party Advisory
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05150888 Third Party Advisory
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05158380 Third Party Advisory
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05176716 Third Party Advisory
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05301946 Third Party Advisory
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05376917 Third Party Advisory
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722 Third Party Advisory
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA40168 Third Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2016-0705
- https://security.FreeBSD.org/advisories/FreeBSD-SA-16:12.openssl.asc vendor-advisoryVendor Advisory
- https://security.gentoo.org/glsa/201603-15 vendor-advisoryThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2016-0705
- https://www.openssl.org/news/secadv/20160301.txt Vendor Advisory
Change history (0)
No recorded changes yet.