Back to search
CVE-2016-8610
Published: Nov 13, 2017
Modified: Aug 6, 2024
PUBLISHED
Description
A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote attacker could use this flaw to make a TLS/SSL server consume an excessive amount of CPU and fail to accept connections from other clients.
| Vendor | Product | Versions |
|---|---|---|
OpenSSL | OpenSSL | affected All 0.9.8affected All 1.0.1affected 1.0.2 through 1.0.2haffected 1.1.0 |
Weaknesses (CWE)
References
93841
vdb-entry
x_refsource_BID
RHSA-2017:1659
vendor-advisory
x_refsource_REDHAT
RHSA-2017:1658
vendor-advisory
x_refsource_REDHAT
RHSA-2017:1801
vendor-advisory
x_refsource_REDHAT
RHSA-2017:0286
vendor-advisory
x_refsource_REDHAT
RHSA-2017:1413
vendor-advisory
x_refsource_REDHAT
RHSA-2017:2494
vendor-advisory
x_refsource_REDHAT
FreeBSD-SA-16:35
vendor-advisory
x_refsource_FREEBSD
RHSA-2017:1414
vendor-advisory
x_refsource_REDHAT
[oss-security] 20161024 CVE-2016-8610: SSL Death Alert: OpenSSL SSL/TLS SSL3_AL_WARNING undefined alert Remote DoS
mailing-list
x_refsource_MLIST
RHSA-2017:0574
vendor-advisory
x_refsource_REDHAT
DSA-3773
vendor-advisory
x_refsource_DEBIAN
RHSA-2017:1415
vendor-advisory
x_refsource_REDHAT
1037084
vdb-entry
x_refsource_SECTRACK
RHSA-2017:1802
vendor-advisory
x_refsource_REDHAT
RHSA-2017:2493
vendor-advisory
x_refsource_REDHAT
https://www.oracle.com/security-alerts/cpuapr2020.html
x_refsource_MISC
https://www.oracle.com/security-alerts/cpujul2020.html
x_refsource_MISC
https://www.oracle.com/security-alerts/cpujan2020.html
x_refsource_MISC
https://security.netapp.com/advisory/ntap-20171130-0001/
x_refsource_CONFIRM
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8610
x_refsource_CONFIRM
https://security.360.cn/cve/CVE-2016-8610/
x_refsource_MISC
https://security.paloaltonetworks.com/CVE-2016-8610
x_refsource_CONFIRM
https://www.oracle.com/security-alerts/cpuoct2020.html
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now