First published: Fri Jan 13 2017(Updated: )
The pstm_exptmod function in MatrixSSL before 3.8.4 allows remote attackers to cause a denial of service (invalid free and crash) via a base zero value for the modular exponentiation.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Matrixssl Matrixssl | <=3.8.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-6885 has a moderate severity rating as it can cause a denial of service due to invalid free and crash.
To fix CVE-2016-6885, upgrade MatrixSSL to version 3.8.4 or later.
The vulnerability affects users of MatrixSSL versions prior to 3.8.4.
CVE-2016-6885 enables a remote denial of service attack through a base zero value for modular exponentiation.
Yes, CVE-2016-6885 can be exploited remotely by attackers.