CVE-2016-6884: XSS
Published Mar 3, 2017
·Updated
TLS cipher suites with CBC mode in TLS 1.1 and 1.2 in MatrixSSL before 3.8.3 allow remote attackers to cause a denial of service (out-of-bounds read) via a crafted message.
Affected Software
1 affected component
MatrixSSL MatrixSSL<=3.8.2
Event History
Mar 3, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
via NVD·04:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-6884?
CVE-2016-6884 is considered a moderate severity vulnerability, as it can lead to denial of service due to out-of-bounds read.
2
How do I fix CVE-2016-6884?
To fix CVE-2016-6884, upgrade MatrixSSL to version 3.8.3 or later.
3
What versions of MatrixSSL are affected by CVE-2016-6884?
MatrixSSL versions prior to 3.8.3, specifically 3.8.2 and earlier, are affected by CVE-2016-6884.
4
What type of attack does CVE-2016-6884 allow?
CVE-2016-6884 allows remote attackers to perform denial of service attacks through carefully crafted TLS messages.
5
Is CVE-2016-6884 related to TLS cipher suites?
Yes, CVE-2016-6884 specifically involves vulnerabilities in TLS cipher suites utilizing the CBC mode in TLS 1.1 and 1.2.