CVE Database
/

CVE-2016-8610

Back to search

CVE-2016-8610

Published: Nov 13, 2017

Modified: Aug 6, 2024

PUBLISHED

Description

A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote attacker could use this flaw to make a TLS/SSL server consume an excessive amount of CPU and fail to accept connections from other clients.

VendorProductVersions

OpenSSL

OpenSSL

affected
All 0.9.8
affected
All 1.0.1
affected
1.0.2 through 1.0.2h
affected
1.1.0

Weaknesses (CWE)

References

93841
vdb-entry
x_refsource_BID
RHSA-2017:1659
vendor-advisory
x_refsource_REDHAT
RHSA-2017:1658
vendor-advisory
x_refsource_REDHAT
RHSA-2017:1801
vendor-advisory
x_refsource_REDHAT
RHSA-2017:0286
vendor-advisory
x_refsource_REDHAT
RHSA-2017:1413
vendor-advisory
x_refsource_REDHAT
RHSA-2017:2494
vendor-advisory
x_refsource_REDHAT
FreeBSD-SA-16:35
vendor-advisory
x_refsource_FREEBSD
RHSA-2017:1414
vendor-advisory
x_refsource_REDHAT
RHSA-2017:0574
vendor-advisory
x_refsource_REDHAT
DSA-3773
vendor-advisory
x_refsource_DEBIAN
RHSA-2017:1415
vendor-advisory
x_refsource_REDHAT
1037084
vdb-entry
x_refsource_SECTRACK
RHSA-2017:1802
vendor-advisory
x_refsource_REDHAT
RHSA-2017:2493
vendor-advisory
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now