OpenSSL released versions 1.0.1u and 1.0.2i to correct multiple vulnerabilities affecting earlier releases. The flaws include DTLS denial-of-service issues: CVE-2016-2181, which lets an attacker advance a connection’s replay-protection window with an unauthenticated future-epoch record and cause valid packets to be discarded, and CVE-2016-2179, which can retain unnecessary out-of-order handshake fragments and consume roughly 1.5 MB of memory per DTLS connection. CVE-2016-6302 can also crash servers using a custom SHA-512 TLS session-ticket HMAC callback through an integer underflow and out-of-bounds read.
The updates additionally address memory-safety defects in certificate and utility processing. CVE-2016-2182 is an out-of-bounds write in BN_bn2dec() caused by unchecked BN_div_word() failures when handling oversized BIGNUM values, while CVE-2016-2180 can cause an out-of-bounds read when the openssl ts utility parses crafted time-stamp data containing large OIDs. CVE-2016-6306 involves a small out-of-bounds read in certificate-message handling when client authentication is enabled. Red Hat issued fixes for affected RHEL 6 and 7 packages, including RHSA-2016:1940, with later JBoss Core Services updates for CVE-2016-2182.

See real exploitation activity before you spend the cycle.
11 events from the most recent confirmed update back to the earliest known activity.
Red Hat marked affected JBoss Core Services on RHEL 6 components as fixed by RHSA-2018:2186 for CVE-2016-6306. The OpenSSL handshake-message out-of-bounds read flaws could allow a remote unauthenticated attacker to crash a TLS/SSL client or server.
Red Hat issued RHSA-2018:2186 to fix CVE-2016-2182 in listed JBoss Core Services on RHEL 6 components, including HTTP Server-related packages. The issue was an unchecked-error out-of-bounds write in OpenSSL's BN_bn2dec() function.
Red Hat released RHSA-2016:1940 for Red Hat Enterprise Linux 6 and 7, fixing CVE-2016-2179 in OpenSSL. A malicious DTLS client could cause unreleased fragment-buffer memory to accumulate and potentially terminate a DTLS server through memory exhaustion.
Red Hat released RHSA-2016:1940 for Red Hat Enterprise Linux 6 and 7, remediating CVE-2016-2181. The vulnerability could let a remote attacker cause an established OpenSSL DTLS connection to reject subsequent client packets.
OpenSSL published its September 2016 security advisory and released 1.0.1u and 1.0.2i, fixing CVE-2016-2179, CVE-2016-2180, CVE-2016-2181, CVE-2016-2182, CVE-2016-6302, and CVE-2016-6306. Users of the affected 1.0.1 and 1.0.2 branches were advised to upgrade.
Shi Lei of Qihoo 360's Gear Team reported CVE-2016-6306 to OpenSSL. Missing certificate-message length checks could cause an out-of-bounds read of up to two bytes when client authentication was enabled.
Shi Lei of Qihoo 360's Gear Team reported CVE-2016-6302 to OpenSSL. A malformed session ticket using a SHA-512 HMAC in a custom ticket configuration could underflow a length value and crash a TLS server.
Shi Lei of Qihoo 360's Gear Team reported CVE-2016-2182 to OpenSSL. Unchecked BN_div_word() failures in BN_bn2dec() could lead to out-of-bounds writes when processing an oversized BIGNUM.
Shi Lei of Qihoo 360's Gear Team reported CVE-2016-2180 to OpenSSL. Large object identifiers processed by the Time-Stamp Protocol code could cause an out-of-bounds read and crash the openssl ts utility.
Quan Luo reported CVE-2016-2179 to OpenSSL. The DTLS handshake logic could retain unneeded out-of-order messages after a handshake, allowing memory exhaustion across many connections.
The OCAP audit team reported CVE-2016-2181 to OpenSSL. The flaw allowed a future-epoch DTLS record with a large sequence number to advance the replay window before MAC validation, enabling denial of service for a connection.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
18 references tracked. Mallory keeps watching after this page renders.
cve.org
Open sourcecve.org
Open sourcecve.org
Open sourcecve.org
Open sourceredhat.com
Open sourceopenssl.org
Open sourcebugzilla.redhat.com
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.