Yuval Yarom, Daniel Genkin, and Nadia Heninger discovered that OpenSSL was vulnerable to a side-channel attack on modular exponentiation. On certain CPUs, a local attacker could possibly use this issue to recover RSA keys. This flaw is known as CacheBleed. (CVE-2016-0702)
Adam Langley discovered that OpenSSL incorrectly handled memory when parsing DSA private keys. A remote attacker could use this issue to cause OpenSSL to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2016-0705)
Guido Vranken discovered that OpenSSL incorrectly handled hex digit calculation in the BN_hex2bn function. A remote attacker could use this issue to cause OpenSSL to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2016-0797)
Emilia Käsper discovered that OpenSSL incorrectly handled memory when performing SRP user database lookups. A remote attacker could possibly use this issue to cause OpenSSL to consume memory, resulting in a denial of service. (CVE-2016-0798)
Guido Vranken discovered that OpenSSL incorrectly handled memory when printing very long strings. A remote attacker could use this issue to cause OpenSSL to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2016-0799)
{ "availability": "No subscription required", "binaries": [ { "binary_version": "1.0.1f-1ubuntu2.18", "binary_name": "libcrypto1.0.0-udeb" }, { "binary_version": "1.0.1f-1ubuntu2.18", "binary_name": "libcrypto1.0.0-udeb-dbgsym" }, { "binary_version": "1.0.1f-1ubuntu2.18", "binary_name": "libssl-dev" }, { "binary_version": "1.0.1f-1ubuntu2.18", "binary_name": "libssl-dev-dbgsym" }, { "binary_version": "1.0.1f-1ubuntu2.18", "binary_name": "libssl-doc" }, { "binary_version": "1.0.1f-1ubuntu2.18", "binary_name": "libssl1.0.0" }, { "binary_version": "1.0.1f-1ubuntu2.18", "binary_name": "libssl1.0.0-dbg" }, { "binary_version": "1.0.1f-1ubuntu2.18", "binary_name": "libssl1.0.0-dbgsym" }, { "binary_version": "1.0.1f-1ubuntu2.18", "binary_name": "libssl1.0.0-udeb" }, { "binary_version": "1.0.1f-1ubuntu2.18", "binary_name": "libssl1.0.0-udeb-dbgsym" }, { "binary_version": "1.0.1f-1ubuntu2.18", "binary_name": "openssl" }, { "binary_version": "1.0.1f-1ubuntu2.18", "binary_name": "openssl-dbgsym" } ] }