CVE-2016-6892: Use After Free
Published Jan 5, 2017
·Updated
The x509FreeExtensions function in MatrixSSL before 3.8.6 allows remote attackers to cause a denial of service (free of unallocated memory) via a crafted X.509 certificate.
Affected Software
1 affected component
MatrixSSL MatrixSSL<=3.8.5
Remediation
Event History
Jan 5, 2017
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-6892?
CVE-2016-6892 has a severity rating that indicates it could lead to denial of service due to improper handling of X.509 certificates.
2
How do I fix CVE-2016-6892?
To fix CVE-2016-6892, update MatrixSSL to version 3.8.6 or later.
3
What type of attack does CVE-2016-6892 allow?
CVE-2016-6892 allows remote attackers to perform a denial of service attack by exploiting vulnerabilities in X.509 certificate processing.
4
In which versions of MatrixSSL is CVE-2016-6892 present?
CVE-2016-6892 is present in all versions of MatrixSSL prior to 3.8.6.
5
What component of MatrixSSL is affected by CVE-2016-6892?
CVE-2016-6892 specifically affects the x509FreeExtensions function in the MatrixSSL library.