Back to search
CVE-2016-0798
Published: Mar 3, 2016
Modified: Aug 5, 2024
PUBLISHED
Description
Memory leak in the SRP_VBASE_get_by_user implementation in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g allows remote attackers to cause a denial of service (memory consumption) by providing an invalid username in a connection attempt, related to apps/s_server.c and crypto/srp/srp_vfy.c.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
openSUSE-SU-2016:0638
vendor-advisory
FreeBSD-SA-16:12
vendor-advisory
SUSE-SU-2016:0621
vendor-advisory
USN-2914-1
vendor-advisory
83705
vdb-entry
DSA-3500
vendor-advisory
91787
vdb-entry
SUSE-SU-2016:0617
vendor-advisory
GLSA-201603-15
vendor-advisory
openSUSE-SU-2016:0628
vendor-advisory
1035133
vdb-entry
SUSE-SU-2016:0620
vendor-advisory
openSUSE-SU-2016:0637
vendor-advisory
openSUSE-SU-2016:0627
vendor-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now