CVE-2016-6885: Use After Free
Published Jan 13, 2017
·Updated
The pstmexptmod function in MatrixSSL before 3.8.4 allows remote attackers to cause a denial of service (invalid free and crash) via a base zero value for the modular exponentiation.
Affected Software
1 affected component
MatrixSSL MatrixSSL<=3.8.3
Remediation
Patch Available
Event History
Jan 13, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
via NVD·04:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-6885?
CVE-2016-6885 has a moderate severity rating as it can cause a denial of service due to invalid free and crash.
2
How do I fix CVE-2016-6885?
To fix CVE-2016-6885, upgrade MatrixSSL to version 3.8.4 or later.
3
Who is affected by CVE-2016-6885?
The vulnerability affects users of MatrixSSL versions prior to 3.8.4.
4
What type of attack does CVE-2016-6885 enable?
CVE-2016-6885 enables a remote denial of service attack through a base zero value for modular exponentiation.
5
Is CVE-2016-6885 exploitable remotely?
Yes, CVE-2016-6885 can be exploited remotely by attackers.