VYPR
High severity7.5NVD Advisory· Published May 5, 2016· Updated May 6, 2026

CVE-2016-2106

CVE-2016-2106

Description

Integer overflow in the EVP_EncryptUpdate function in crypto/evp/evp_enc.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (heap memory corruption) via a large amount of data.

Affected products

23
  • cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*+ 11 more
    • cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*range: <=1.0.1s
    • cpe:2.3:a:openssl:openssl:1.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:1.0.2a:*:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:1.0.2b:*:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:1.0.2:beta1:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:1.0.2:beta2:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:1.0.2:beta3:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:1.0.2c:*:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:1.0.2d:*:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:1.0.2e:*:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:1.0.2f:*:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:1.0.2g:*:*:*:*:*:*:*
  • cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
    • cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
  • cpe:2.3:o:redhat:enterprise_linux_hpc_node:6.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:redhat:enterprise_linux_hpc_node:6.0:*:*:*:*:*:*:*
    • cpe:2.3:o:redhat:enterprise_linux_hpc_node:7.0:*:*:*:*:*:*:*
  • cpe:2.3:o:redhat:enterprise_linux_hpc_node_eus:7.2:*:*:*:*:*:*:*
  • cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
    • cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
  • cpe:2.3:o:redhat:enterprise_linux_server_aus:7.2:*:*:*:*:*:*:*
  • cpe:2.3:o:redhat:enterprise_linux_server_eus:7.2:*:*:*:*:*:*:*
  • cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*
    • cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

60

News mentions

0

No linked articles in our index yet.