First published: Fri Mar 03 2017(Updated: )
TLS cipher suites with CBC mode in TLS 1.1 and 1.2 in MatrixSSL before 3.8.3 allow remote attackers to cause a denial of service (out-of-bounds read) via a crafted message.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Matrixssl Matrixssl | <=3.8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-6884 is considered a moderate severity vulnerability, as it can lead to denial of service due to out-of-bounds read.
To fix CVE-2016-6884, upgrade MatrixSSL to version 3.8.3 or later.
MatrixSSL versions prior to 3.8.3, specifically 3.8.2 and earlier, are affected by CVE-2016-6884.
CVE-2016-6884 allows remote attackers to perform denial of service attacks through carefully crafted TLS messages.
Yes, CVE-2016-6884 specifically involves vulnerabilities in TLS cipher suites utilizing the CBC mode in TLS 1.1 and 1.2.