CVE-2016-6302
CVE-2016-6302
The tls_decrypt_ticket function in ssl/t1_lib.c in OpenSSL before 1.1.0 does not consider the HMAC size during validation of the ticket length, which allows remote attackers to cause a denial of service via a ticket that is too short.
Produtos afetados
n/a · n/aQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10759http://rhn.redhat.com/errata/RHSA-2016-1940.htmlhttps://access.redhat.com/errata/RHSA-2018:2185https://access.redhat.com/errata/RHSA-2018:2186https://access.redhat.com/errata/RHSA-2018:2187https://bto.bluecoat.com/security-advisory/sa132https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdfhttps://git.openssl.org/?p=openssl.git%3Ba=commit%3Bh=e97763c92c655dcf4af2860b3abd2bc4c8a267f9https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA40312https://security.FreeBSD.org/advisories/FreeBSD-SA-16:26.openssl.aschttps://www.tenable.com/security/tns-2016-16https://www.tenable.com/security/tns-2016-20