OpenSSL released 1.1.0c to remediate three vulnerabilities in the 1.1.0 branch, led by CVE-2016-7054, a high-severity heap-buffer overflow in ChaCha20/Poly1305 processing. A remote attacker could send a large malformed payload to TLS services using *-CHACHA20-POLY1305 cipher suites and crash the affected OpenSSL process, creating a denial-of-service condition. The release also fixes CVE-2016-7053, a CMS NULL-pointer dereference, and CVE-2016-7055, a Montgomery multiplication issue; the latter also affects 1.0.2.x and was slated for a subsequent 1.0.2 update.
Administrators running OpenSSL 1.1.0 should upgrade to 1.1.0c. The flaws do not affect SSL/TLS certificates, so certificate replacement or revocation is not required. Organizations should also remove obsolete OpenSSL branches from production: versions 0.9.8 and 1.0.0 were already unsupported, and support for 1.0.1 was scheduled to end on 31 December 2016.

See real exploitation activity before you spend the cycle.
9 events from the most recent confirmed update back to the earliest known activity.
Tyler Nighswander of ForAllSecure reported CVE-2016-7053 to OpenSSL. The moderate-severity flaw could cause applications parsing invalid CMS structures to crash through a NULL-pointer dereference.
OpenSSL's security advisory rated CVE-2016-6309 as critical and identified it as a use-after-free flaw in OpenSSL 1.1.0a, introduced by the prior CVE-2016-6307 fix. The related 1.1.0b and 1.0.2j patches addressed CVE-2016-6309 and the moderate CRL null-pointer crash CVE-2016-7052.
Robert Święcki of Google's Security Team reported CVE-2016-7054 to OpenSSL using honggfuzz. The high-severity heap-buffer overflow could crash TLS services using ChaCha20/Poly1305 cipher suites when supplied a large corrupted payload.
OpenSSL published a security advisory listing vulnerabilities addressed by releases 1.0.2f and 1.0.1r, including a high-severity flaw affecting the 1.0.2 branch and an SSLv2-handshake issue affecting 1.0.2 and 1.0.1. The release also raised the minimum accepted handshake size to 1024 bits as Logjam-related hardening.
OpenSSL versions 0.9.8 and 1.0.0 ceased receiving support and security updates. OpenSSL stated that no further patches would be issued for those branches.
OpenSSL published an advisory covering CVE-2016-7054, CVE-2016-7053, and CVE-2016-7055, and released OpenSSL 1.1.0c to remediate the three flaws in the 1.1.0 branch. The advisory noted that the 1.0.2 fix for the low-severity Montgomery multiplication issue CVE-2016-7055 was deferred to a subsequent 1.0.2 release.
OpenSSL released versions 1.1.0a, 1.0.2i, and 1.0.1u to fix 14 vulnerabilities. The most serious, CVE-2016-6304, allowed repeated renegotiation with large OCSP Status Request extensions to exhaust server memory and cause denial of service.
OpenSSL released versions 1.0.2g and 1.0.1s to remediate seven vulnerabilities, including the high-severity DROWN cross-protocol attack. DROWN could permit decryption of TLS sessions where a server supported SSLv2 and EXPORT ciphers as a Bleichenbacher RSA padding oracle.
OpenSSL released versions 1.0.2b, 1.0.1n, 1.0.0s, and 0.9.8zg to address six newly discovered vulnerabilities, five rated moderate risk and one low risk. The project advised administrators to upgrade affected installations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
7 references tracked. Mallory keeps watching after this page renders.
digicert.com
Open sourcedigicert.com
Open sourcedigicert.com
Open sourceopenssl.org
Open sourcedigicert.com
Open sourcedigicert.com
Open sourcedigicert.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.