CVE-2016-2182: Critical severity Google Android vulnerability
An out of bounds write flaw was discovered in the OpenSSL BNbn2dec() function. An attacker able to make an application using OpenSSL to process a large BIGNUM could cause the application to crash or, possibly, execute arbitrary code.
Other sources
An out-of-bounds write vulnerability was found to be caused by not checking errors in BNbn2dec(). If an oversize BIGNUM is presented to BNbn2dec() it can cause BNdivword() to fail and not reduce the value of 't' resulting in OOB writes to the bndata buffer and eventually crashing.
Upstream patch:
https://git.openssl.org/?p=openssl.git;a=commit;h=07bed46f332fce8c1d157689a2cdf915a982ae34
— Red Hat
The BNbn2dec function in crypto/bn/bnprint.c in OpenSSL before 1.1.0 does not properly validate division results, which allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or possibly have unspecified other impact via unknown vectors.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/jbcs-httpd24-apache-commons-daemonto a version that resolves this vulnerability.Fixed in 0:1.1.0-1.redhat_2.1.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-apache-commons-daemon-jsvcto a version that resolves this vulnerability.Fixed in 1:1.1.0-1.redhat_2.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-aprto a version that resolves this vulnerability.Fixed in 0:1.6.3-14.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-apr-utilto a version that resolves this vulnerability.Fixed in 0:1.6.1-9.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-httpdto a version that resolves this vulnerability.Fixed in 0:2.4.29-17.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-nghttp2to a version that resolves this vulnerability.Fixed in 0:1.29.0-8.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-opensslto a version that resolves this vulnerability.Fixed in 1:1.0.2n-11.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-apache-commons-daemonto a version that resolves this vulnerability.Fixed in 0:1.1.0-1.redhat_2.1.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-apache-commons-daemon-jsvcto a version that resolves this vulnerability.Fixed in 1:1.1.0-1.redhat_2.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-aprto a version that resolves this vulnerability.Fixed in 0:1.6.3-14.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-apr-utilto a version that resolves this vulnerability.Fixed in 0:1.6.1-9.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-httpdto a version that resolves this vulnerability.Fixed in 0:2.4.29-17.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-nghttp2to a version that resolves this vulnerability.Fixed in 0:1.29.0-8.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-opensslto a version that resolves this vulnerability.Fixed in 1:1.0.2n-11.jbcs.el7 - Upgrade
Upgrade
redhat/opensslto a version that resolves this vulnerability.Fixed in 0:1.0.1e-48.el6_8.3 - Upgrade
Upgrade
redhat/opensslto a version that resolves this vulnerability.Fixed in 1:1.0.1e-51.el7_2.7 - Upgrade
Upgrade
debian/opensslto a version that resolves this vulnerability.Fixed in 1.1.1w-0+deb11u1Fixed in 1.1.1w-0+deb11u2Fixed in 3.0.15-1~deb12u1Fixed in 3.0.14-1~deb12u2Fixed in 3.4.1-1 - Upgrade
Upgrade
redhat/opensslto a version that resolves this vulnerability.Fixed in 1.0.1 - Upgrade
Upgrade
redhat/opensslto a version that resolves this vulnerability.Fixed in 1.0.2 - Upgrade
Upgrade
debian/opensslto a version that resolves this vulnerability.Fixed in 1.1.1w-0+deb11u1 - Upgrade
Upgrade
debian/opensslto a version that resolves this vulnerability.Fixed in 1.1.1w-0+deb11u2 - Upgrade
Upgrade
debian/opensslto a version that resolves this vulnerability.Fixed in 3.0.15-1~deb12u1 - Upgrade
Upgrade
debian/opensslto a version that resolves this vulnerability.Fixed in 3.0.14-1~deb12u2 - Upgrade
Upgrade
debian/opensslto a version that resolves this vulnerability.Fixed in 3.4.1-1 - Upgrade
Upgrade
OpenSSLto a version that resolves this vulnerability.Patch 07bed46f332fce8c1d157689a2cdf915a982ae34
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2016-2182?
CVE-2016-2182 has a high severity rating due to its potential to allow an attacker to crash an application or execute arbitrary code.
How do I fix CVE-2016-2182?
To fix CVE-2016-2182, update your OpenSSL package to a version that is patched against this vulnerability.
Which software is affected by CVE-2016-2182?
CVE-2016-2182 affects various Red Hat packages including jbcs-httpd24-apache-commons-daemon and openssl among others.
What types of attacks can CVE-2016-2182 facilitate?
CVE-2016-2182 can facilitate denial of service attacks by crashing applications or may allow for arbitrary code execution.
Is there a recommended version to upgrade to for CVE-2016-2182?
Recommended versions to upgrade to include OpenSSL 1.1.0 or later, which addresses the issues posed by CVE-2016-2182.