CVE-2016-2180: High severity OpenSSL OpenSSL vulnerability

Published Jul 21, 2016
·
Updated

An OOB read flaw was found in the RFC 3161 Public Key Infrastructure Time-Stamp Protocol code of OpenSSL. An attacker could use this flaw to cause the openssl binary to crash when specially-crafted time-stamp file is parsed via the "openssl ts" command.

Upstream commit:

master: https://github.com/openssl/openssl/commit/0ed26acce328ec16a3aa635f1ca37365e8c7403a 1.0.1: https://github.com/openssl/openssl/commit/6adf409c7432b90c06d9890787fe56c48f2a16e7

Other sources

An out of bounds read flaw was found in the way OpenSSL formatted Public Key Infrastructure Time-Stamp Protocol data for printing. An attacker could possibly cause an application using OpenSSL to crash if it printed time stamp data from the attacker.

The TSOBJprintbio function in crypto/ts/tslib.c in the X.509 Public Key Infrastructure Time-Stamp Protocol (TSP) implementation in OpenSSL through 1.0.2h allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted time-stamp file that is mishandled by the "openssl ts" command.

Affected Software

37 affected componentsFixes available
redhat/openssl<0:1.0.1e-48.el6_8.3
0:1.0.1e-48.el6_8.3
redhat/openssl<1:1.0.1e-51.el7_2.7
1:1.0.1e-51.el7_2.7
redhat/openssl<1.0.1
1.0.1
redhat/openssl<1.0.2
1.0.2
OpenSSL OpenSSL=1.0.1
OpenSSL OpenSSL=1.0.1a
OpenSSL OpenSSL=1.0.1b
OpenSSL OpenSSL=1.0.1c
OpenSSL OpenSSL=1.0.1d
OpenSSL OpenSSL=1.0.1e
OpenSSL OpenSSL=1.0.1f
OpenSSL OpenSSL=1.0.1g
OpenSSL OpenSSL=1.0.1h
OpenSSL OpenSSL=1.0.1i
OpenSSL OpenSSL=1.0.1j
OpenSSL OpenSSL=1.0.1k
OpenSSL OpenSSL=1.0.1l
OpenSSL OpenSSL=1.0.1m
OpenSSL OpenSSL=1.0.1n
OpenSSL OpenSSL=1.0.1o
OpenSSL OpenSSL=1.0.1p
OpenSSL OpenSSL=1.0.1q
OpenSSL OpenSSL=1.0.1r
OpenSSL OpenSSL=1.0.1s
OpenSSL OpenSSL=1.0.1t
OpenSSL OpenSSL=1.0.2
OpenSSL OpenSSL=1.0.2a
OpenSSL OpenSSL=1.0.2b
OpenSSL OpenSSL=1.0.2c
OpenSSL OpenSSL=1.0.2d
OpenSSL OpenSSL=1.0.2e
OpenSSL OpenSSL=1.0.2f
OpenSSL OpenSSL=1.0.2g
OpenSSL OpenSSL=1.0.2h
ORACLE Linux=6
ORACLE Linux=7
debian/openssl
1.1.1w-0+deb11u11.1.1w-0+deb11u23.0.15-1~deb12u13.0.14-1~deb12u23.4.1-1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade redhat/openssl to a version that resolves this vulnerability.

    Fixed in 0:1.0.1e-48.el6_8.3
  2. Upgrade

    Upgrade redhat/openssl to a version that resolves this vulnerability.

    Fixed in 1:1.0.1e-51.el7_2.7
  3. Upgrade

    Upgrade debian/openssl to a version that resolves this vulnerability.

    Fixed in 1.1.1w-0+deb11u1Fixed in 1.1.1w-0+deb11u2Fixed in 3.0.15-1~deb12u1Fixed in 3.0.14-1~deb12u2Fixed in 3.4.1-1
  4. Upgrade

    Upgrade redhat/openssl to a version that resolves this vulnerability.

    Fixed in 1.0.1
  5. Upgrade

    Upgrade redhat/openssl to a version that resolves this vulnerability.

    Fixed in 1.0.2
  6. Upgrade

    Upgrade OpenSSL to a version that resolves this vulnerability.

    Patch 0ed26acce328ec16a3aa635f1ca37365e8c7403a
  7. Upgrade

    Upgrade OpenSSL to a version that resolves this vulnerability.

    Patch 6adf409c7432b90c06d9890787fe56c48f2a16e7
  8. Compensating control

    Avoid parsing attacker-supplied RFC 3161 time-stamp data with the OpenSSL "openssl ts" command until the fix from the upstream commits is applied.

Event History

Jul 21, 2016
CVE Published
12:00 AM
Jul 25, 2016
Data Sourced
via Red Hat·06:53 AM
DescriptionSeverityAffected Software
Aug 1, 2016
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Jan 11, 2024
Data Sourced
via Launchpad·10:16 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·01:12 AM
RemedyDescriptionSeverityAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2016-2180?

CVE-2016-2180 is categorized as a medium severity vulnerability.

2

How do I fix CVE-2016-2180?

To fix CVE-2016-2180, update OpenSSL to version 1.0.1 or higher as specified in remediation guidelines.

3

What kind of vulnerability is CVE-2016-2180?

CVE-2016-2180 is an out-of-bounds read vulnerability that can lead to a crash of the openssl binary.

4

Which OpenSSL versions are affected by CVE-2016-2180?

Affected OpenSSL versions include 1.0.1 through 1.0.1e and older versions.

5

What can an attacker achieve with CVE-2016-2180?

An attacker can exploit CVE-2016-2180 to make the openssl binary crash by parsing specially-crafted time-stamp files.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203