CVE-2016-2106: Integer Overflow

Published Apr 28, 2016
·
Updated

An integer overflow flaw, leading to a buffer overflow, was found in the way the EVPEncryptUpdate() function of OpenSSL parsed very large amounts of input data. A remote attacker could use this flaw to crash an application using OpenSSL or, possibly, execute arbitrary code with the permissions of the user running that application.

Other sources

Integer overflow in the EVPEncryptUpdate function in crypto/evp/evpenc.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (heap memory corruption) via a large amount of data.

Quoting form the draft of OpenSSL upstream advisory:

EVPEncryptUpdate overflow (CVE-2016-2106) ==========================================

Severity: Low

An overflow can occur in the EVPEncryptUpdate() function. If an attacker is able to supply very large amounts of input data after a previous call to EVPEncryptUpdate() with a partial block then a length check can overflow resulting in a heap corruption. Following an analysis of all OpenSSL internal usage of the EVPEncryptUpdate() function all usage is one of two forms. The first form is where the EVPEncryptUpdate() call is known to be the first called function after an EVPEncryptInit(), and therefore that specific call must be safe. The second form is where the length passed to EVPEncryptUpdate() can be seen from the code to be some small value and therefore there is no possibility of an overflow. Since all instances are one of these two forms, it is believed that there can be no overflows in internal code due to this problem. It should be noted that EVPDecryptUpdate() can call EVPEncryptUpdate() in certain code paths. Also EVPCipherUpdate() is a synonym for EVPEncryptUpdate(). All instances of these calls have also been too and it is believed there are no instances in internal usage where an overflow could occur.

This could still represent a security issue for end user code that calls this function directly.

OpenSSL 1.0.2 users should upgrade to 1.0.2h OpenSSL 1.0.1 users should upgrade to 1.0.1t

This issue was reported to OpenSSL on 3rd March 2016 by Guido Vranken. The fix was developed by Matt Caswell of the OpenSSL development team.

Affected Software

36 affected componentsFixes available
redhat/openssl<1.0.1
1.0.1
redhat/openssl<1.0.2
1.0.2
redhat/openssl<0:1.0.1e-48.el6_8.1
0:1.0.1e-48.el6_8.1
redhat/openssl<0:1.0.1e-42.el6_7.5
0:1.0.1e-42.el6_7.5
redhat/openssl<1:1.0.1e-51.el7_2.5
1:1.0.1e-51.el7_2.5
redhat/httpd<0:2.2.26-54.ep6.el6
0:2.2.26-54.ep6.el6
redhat/jbcs-httpd24<0:1-3.jbcs.el6
0:1-3.jbcs.el6
redhat/jbcs-httpd24-openssl<1:1.0.2h-4.jbcs.el6
1:1.0.2h-4.jbcs.el6
redhat/tomcat-native<0:1.1.34-5.redhat_1.ep6.el6
0:1.1.34-5.redhat_1.ep6.el6
redhat/httpd22<0:2.2.26-56.ep6.el7
0:2.2.26-56.ep6.el7
redhat/jbcs-httpd24<0:1-3.jbcs.el7
0:1-3.jbcs.el7
redhat/jbcs-httpd24-openssl<1:1.0.2h-4.jbcs.el7
1:1.0.2h-4.jbcs.el7
redhat/tomcat-native<0:1.1.34-5.redhat_1.ep6.el7
0:1.1.34-5.redhat_1.ep6.el7
OpenSSL OpenSSL<=1.0.1s
OpenSSL OpenSSL=1.0.2
OpenSSL OpenSSL=1.0.2-beta1
OpenSSL OpenSSL=1.0.2-beta2
OpenSSL OpenSSL=1.0.2-beta3
OpenSSL OpenSSL=1.0.2a
OpenSSL OpenSSL=1.0.2b
OpenSSL OpenSSL=1.0.2c
OpenSSL OpenSSL=1.0.2d
OpenSSL OpenSSL=1.0.2e
OpenSSL OpenSSL=1.0.2f
OpenSSL OpenSSL=1.0.2g
redhat Enterprise Linux Desktop=7.0
redhat Enterprise Linux Hpc Node=7.0
redhat Enterprise Linux Hpc Node Eus=7.2
redhat Enterprise Linux Server=7.0
redhat Enterprise Linux Server Aus=7.2
redhat Enterprise Linux Server Eus=7.2
redhat Enterprise Linux Workstation=7.0
redhat Enterprise Linux Desktop=6.0
redhat Enterprise Linux Hpc Node=6.0
redhat Enterprise Linux Server=6.0
redhat Enterprise Linux Workstation=6.0

Event History

May 3, 2016
CVE Published
12:00 AM
May 5, 2016
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-2016-2106?

CVE-2016-2106 is considered a high severity vulnerability due to the potential for buffer overflow and remote code execution.

2

How do I fix CVE-2016-2106?

To fix CVE-2016-2106, you should upgrade OpenSSL to version 1.0.1s or 1.0.2h, or apply the relevant patches provided by your distribution.

3

What types of applications are affected by CVE-2016-2106?

Applications that utilize OpenSSL for encryption functions, particularly those using EVP_EncryptUpdate, are affected by CVE-2016-2106.

4

Can CVE-2016-2106 lead to remote code execution?

Yes, if exploited, CVE-2016-2106 can allow an attacker to execute arbitrary code on the affected system with the privileges of the application using OpenSSL.

5

Which OpenSSL versions are vulnerable to CVE-2016-2106?

OpenSSL versions 1.0.1 and 1.0.2 prior to 1.0.2h are vulnerable to CVE-2016-2106.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203