Back

HIGH

OpenSSL: Avoid memory leak in SRP

Published Mar 3, 2016

Description

Memory leak in the SRP_VBASE_get_by_user implementation in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g allows remote attackers to cause a denial of service (memory consumption) by providing an invalid username in a connection attempt, related to apps/s_server.c and crypto/srp/srp_vfy.c.

Affected products

Remediation

Red Hat statement

This issue does not affect the version of OpenSSL shipped with Red Hat Enterprise Linux 5, 6 and 7, since these packages are compiled without SRP support.

Metrics

Weaknesses (1)

References (29)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Mar 3, 2016
Updated Aug 5, 2024
Reserved Dec 16, 2015
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Feb 25, 2016