A denial of service flaw was found in OpenSSL 0.9.8,...
Vulnerability Description
A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote attacker could use this flaw to make a TLS/SSL server consume an excessive amount of CPU and fail to accept connections from other clients.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2016-8610
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.securityfocus.com/bid/93841
- http://rhn.redhat.com/errata/RHSA-2017-1659.html
- https://access.redhat.com/errata/RHSA-2017:1658
- https://access.redhat.com/errata/RHSA-2017:1801
- http://rhn.redhat.com/errata/RHSA-2017-0286.html
- https://access.redhat.com/errata/RHSA-2017:1413
- https://access.redhat.com/errata/RHSA-2017:2494
- https://security.FreeBSD.org/advisories/FreeBSD-SA-16:35.openssl.asc
- https://access.redhat.com/errata/RHSA-2017:1414
- http://seclists.org/oss-sec/2016/q4/224
- http://rhn.redhat.com/errata/RHSA-2017-0574.html
- https://www.debian.org/security/2017/dsa-3773
- http://rhn.redhat.com/errata/RHSA-2017-1415.html
- http://www.securitytracker.com/id/1037084
- https://access.redhat.com/errata/RHSA-2017:1802
- https://access.redhat.com/errata/RHSA-2017:2493
- https://www.oracle.com/security-alerts/cpuapr2020.html
- https://www.oracle.com/security-alerts/cpujul2020.html
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
- https://www.oracle.com/security-alerts/cpujan2020.html
- https://security.netapp.com/advisory/ntap-20171130-0001/
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8610
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commit%3Bh=af58be768ebb690f78530f796e92b8ae5c9a4401
- https://security.360.cn/cve/CVE-2016-8610/
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03897en_us
- https://security.paloaltonetworks.com/CVE-2016-8610
- https://www.oracle.com/security-alerts/cpuoct2020.html
More from OpenSSL
View All →Affected Vendor
OpenSSL
View all reports →