CVE-2016-6886: XSS
Published Jan 13, 2017
·Updated
The pstmreverse function in MatrixSSL before 3.8.4 allows remote attackers to cause a denial of service (invalid memory read and crash) via a (1) zero value or (2) the key's modulus for the secret key during RSA key exchange.
Affected Software
1 affected component
MatrixSSL MatrixSSL<=3.8.3
Remediation
Patch Available
Event History
Jan 13, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
via NVD·04:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-6886?
CVE-2016-6886 has been classified as a denial of service vulnerability.
2
What causes the CVE-2016-6886 vulnerability?
CVE-2016-6886 is caused by the pstm_reverse function in MatrixSSL allowing invalid memory reads during RSA key exchange.
3
How do I fix CVE-2016-6886?
To fix CVE-2016-6886, upgrade MatrixSSL to version 3.8.4 or later.
4
Which versions of MatrixSSL are affected by CVE-2016-6886?
MatrixSSL versions prior to 3.8.4 are affected by CVE-2016-6886.
5
Is there a known exploit for CVE-2016-6886?
As of now, specific exploit codes for CVE-2016-6886 have not been publicly disclosed.