CVE-2016-6891: XSS
Published Jan 5, 2017
·Updated
MatrixSSL before 3.8.6 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted ASN.1 Bit Field primitive in an X.509 certificate.
Affected Software
1 affected component
MatrixSSL MatrixSSL<=3.8.5
Remediation
Event History
Jan 5, 2017
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-6891?
CVE-2016-6891 is rated as a medium severity vulnerability due to potential denial of service through an out-of-bounds read.
2
How do I fix CVE-2016-6891?
To mitigate CVE-2016-6891, update MatrixSSL to version 3.8.6 or later.
3
What types of attacks can exploit CVE-2016-6891?
CVE-2016-6891 can be exploited through crafted ASN.1 Bit Field primitives in X.509 certificates to cause denial of service.
4
Which versions of MatrixSSL are affected by CVE-2016-6891?
CVE-2016-6891 affects MatrixSSL versions prior to 3.8.6.
5
Is CVE-2016-6891 specific to any particular platform?
CVE-2016-6891 is not platform-specific, as it affects the MatrixSSL library used in various software applications.