CVE-2016-6890: Buffer Overflow
Published Jan 5, 2017
·Updated
Heap-based buffer overflow in MatrixSSL before 3.8.6 allows remote attackers to execute arbitrary code via a crafted Subject Alt Name in an X.509 certificate.
Affected Software
1 affected component
MatrixSSL MatrixSSL<=3.8.5
Remediation
Event History
Jan 5, 2017
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-6890?
CVE-2016-6890 has been classified as critical due to the potential for remote code execution.
2
How do I fix CVE-2016-6890?
To fix CVE-2016-6890, upgrade to MatrixSSL version 3.8.6 or later.
3
What types of attacks can exploit CVE-2016-6890?
CVE-2016-6890 can be exploited by remote attackers using a crafted Subject Alt Name in an X.509 certificate.
4
Which versions of MatrixSSL are affected by CVE-2016-6890?
CVE-2016-6890 affects all MatrixSSL versions prior to 3.8.6.
5
Is there a workaround for CVE-2016-6890 if I cannot upgrade?
There are no known workarounds for CVE-2016-6890, so upgrading is strongly recommended.