Back

CRITICAL

openssl: doapr_outch function does not verify that certain memory allocation succeeds

Published Mar 3, 2016

Description

The doapr_outch function in crypto/bio/b_print.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g does not verify that a certain memory allocation succeeds, which allows remote attackers to cause a denial of service (out-of-bounds write or memory consumption) or possibly have unspecified other impact via a long string, as demonstrated by a large amount of ASN.1 data, a different vulnerability than CVE-2016-0799.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (31)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 3, 2016
Updated Aug 5, 2024
Reserved Mar 3, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Mar 3, 2016