CVE 2016-2180
The TS_OBJ_print_bio function in crypto/ts/ts_lib.c in the X.509 Public Key Infrastructure Time-Stamp Protocol (TSP) implementation in OpenSSL through 1.0.2h allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted time-stamp file that is mishandled by the "openssl ts" command.
Related bugs and status
CVE-2016-2180 (Candidate) is related to these bugs:
Bug #1593953: EC_KEY_generate_key() causes FIPS self-test failure
Summary | In | Importance | Status | |||
---|---|---|---|---|---|---|
1593953 | EC_KEY_generate_key() causes FIPS self-test failure | openssl (Ubuntu) | Undecided | Fix Released | ||
1593953 | EC_KEY_generate_key() causes FIPS self-test failure | openssl (Ubuntu Xenial) | Undecided | Fix Released |
Bug #1594748: CRYPTO_set_mem_functions() is broken
Summary | In | Importance | Status | |||
---|---|---|---|---|---|---|
1594748 | CRYPTO_set_mem_functions() is broken | openssl (Ubuntu) | Undecided | Fix Released | ||
1594748 | CRYPTO_set_mem_functions() is broken | OpenSSL | Unknown | Invalid | ||
1594748 | CRYPTO_set_mem_functions() is broken | openssl (Ubuntu Xenial) | Undecided | Fix Released |
Bug #1614210: Remove incomplete fips in openssl in xenial.
Summary | In | Importance | Status | |||
---|---|---|---|---|---|---|
1614210 | Remove incomplete fips in openssl in xenial. | openssl (Ubuntu) | Undecided | Fix Released | ||
1614210 | Remove incomplete fips in openssl in xenial. | openssl (Ubuntu Xenial) | Undecided | Fix Released | ||
1614210 | Remove incomplete fips in openssl in xenial. | openssl (Ubuntu Yakkety) | Undecided | Fix Released |
Bug #1622500: Backported bugfix for CVE-2014-3571 causes regressions for DTLS in Ubuntu 14.04
Summary | In | Importance | Status | |||
---|---|---|---|---|---|---|
1622500 | Backported bugfix for CVE-2014-3571 causes regressions for DTLS in Ubuntu 14.04 | openssl (Ubuntu) | Undecided | Invalid | ||
1622500 | Backported bugfix for CVE-2014-3571 causes regressions for DTLS in Ubuntu 14.04 | openssl (Ubuntu Trusty) | Undecided | Fix Released | ||
1622500 | Backported bugfix for CVE-2014-3571 causes regressions for DTLS in Ubuntu 14.04 | openssl (Ubuntu Precise) | Undecided | Fix Released |
Bug #1811531: remote execution vulnerability
Summary | In | Importance | Status | |||
---|---|---|---|---|---|---|
1811531 | remote execution vulnerability | zeromq3 (Ubuntu) | Undecided | Fix Released | ||
1811531 | remote execution vulnerability | zeromq3 (Debian) | Unknown | Fix Released | ||
1811531 | remote execution vulnerability | zeromq (Suse) | High | Fix Released |
See the
CVE page on Mitre.org
for more details.