BSA-2017-281

Brocade Fabric OS

2 more products

21367

15 January 2019

17 May 2017

Closed

Medium

9.8

N/A

CVE-2016-2842

Summary

Security Advisory ID : BSA-2017-281

Component : OpenSSL

Revision : 3.0: Final

The doapr_outch function in crypto/bio/b_print.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g does not verify that a certain memory allocation succeeds, which allows remote attackers to cause a denial of service (out-of-bounds write or memory consumption) or possibly have unspecified other impact via a long string, as demonstrated by a large amount of ASN.1 data, a different vulnerability than CVE-2016-0799.


Products Confirmed Not Vulnerable

No Brocade Fibre Channel technology products from Broadcom are currently known to be affected by this vulnerability.

 

Revision History

Version Change Date
1.0 Initial Publication May 17, 2017
2.0 Update Fabric OS Status May 22, 2017
3.0 Updated for Fibre Channel Only Jan 15, 2019