First published: Fri Jan 13 2017(Updated: )
The pstm_reverse function in MatrixSSL before 3.8.4 allows remote attackers to cause a denial of service (invalid memory read and crash) via a (1) zero value or (2) the key's modulus for the secret key during RSA key exchange.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Matrixssl Matrixssl | <=3.8.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-6886 has been classified as a denial of service vulnerability.
CVE-2016-6886 is caused by the pstm_reverse function in MatrixSSL allowing invalid memory reads during RSA key exchange.
To fix CVE-2016-6886, upgrade MatrixSSL to version 3.8.4 or later.
MatrixSSL versions prior to 3.8.4 are affected by CVE-2016-6886.
As of now, specific exploit codes for CVE-2016-6886 have not been publicly disclosed.