CVE 2016-2181
The Anti-Replay feature in the DTLS implementation in OpenSSL before 1.1.0 mishandles early use of a new epoch number in conjunction with a large sequence number, which allows remote attackers to cause a denial of service (false-positive packet drops) via spoofed DTLS records, related to rec_layer_d1.c and ssl3_record.c.
Related bugs and status
CVE-2016-2181 (Candidate) is related to these bugs:
Bug #1593953: EC_KEY_generate_key() causes FIPS self-test failure
Summary | In | Importance | Status | |||
---|---|---|---|---|---|---|
1593953 | EC_KEY_generate_key() causes FIPS self-test failure | openssl (Ubuntu) | Undecided | Fix Released | ||
1593953 | EC_KEY_generate_key() causes FIPS self-test failure | openssl (Ubuntu Xenial) | Undecided | Fix Released |
Bug #1594748: CRYPTO_set_mem_functions() is broken
Summary | In | Importance | Status | |||
---|---|---|---|---|---|---|
1594748 | CRYPTO_set_mem_functions() is broken | openssl (Ubuntu) | Undecided | Fix Released | ||
1594748 | CRYPTO_set_mem_functions() is broken | OpenSSL | Unknown | Invalid | ||
1594748 | CRYPTO_set_mem_functions() is broken | openssl (Ubuntu Xenial) | Undecided | Fix Released |
Bug #1614210: Remove incomplete fips in openssl in xenial.
Summary | In | Importance | Status | |||
---|---|---|---|---|---|---|
1614210 | Remove incomplete fips in openssl in xenial. | openssl (Ubuntu) | Undecided | Fix Released | ||
1614210 | Remove incomplete fips in openssl in xenial. | openssl (Ubuntu Xenial) | Undecided | Fix Released | ||
1614210 | Remove incomplete fips in openssl in xenial. | openssl (Ubuntu Yakkety) | Undecided | Fix Released |
Bug #1622500: Backported bugfix for CVE-2014-3571 causes regressions for DTLS in Ubuntu 14.04
Summary | In | Importance | Status | |||
---|---|---|---|---|---|---|
1622500 | Backported bugfix for CVE-2014-3571 causes regressions for DTLS in Ubuntu 14.04 | openssl (Ubuntu) | Undecided | Invalid | ||
1622500 | Backported bugfix for CVE-2014-3571 causes regressions for DTLS in Ubuntu 14.04 | openssl (Ubuntu Trusty) | Undecided | Fix Released | ||
1622500 | Backported bugfix for CVE-2014-3571 causes regressions for DTLS in Ubuntu 14.04 | openssl (Ubuntu Precise) | Undecided | Fix Released |
Bug #1811531: remote execution vulnerability
Summary | In | Importance | Status | |||
---|---|---|---|---|---|---|
1811531 | remote execution vulnerability | zeromq3 (Ubuntu) | Undecided | Fix Released | ||
1811531 | remote execution vulnerability | zeromq3 (Debian) | Unknown | Fix Released | ||
1811531 | remote execution vulnerability | zeromq (Suse) | High | Fix Released |
See the
CVE page on Mitre.org
for more details.