VYPR
High severity7.5NVD Advisory· Published Sep 16, 2016· Updated May 6, 2026

CVE-2016-6302

CVE-2016-6302

Description

The tls_decrypt_ticket function in ssl/t1_lib.c in OpenSSL before 1.1.0 does not consider the HMAC size during validation of the ticket length, which allows remote attackers to cause a denial of service via a ticket that is too short.

Affected products

34
  • cpe:2.3:a:openssl:openssl:1.0.1:*:*:*:*:*:*:*+ 29 more
    • cpe:2.3:a:openssl:openssl:1.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:1.0.1a:*:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:1.0.1b:*:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:1.0.1c:*:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:1.0.1d:*:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:1.0.1e:*:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:1.0.1f:*:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:1.0.1g:*:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:1.0.1h:*:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:1.0.1i:*:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:1.0.1j:*:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:1.0.1k:*:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:1.0.1l:*:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:1.0.1m:*:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:1.0.1n:*:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:1.0.1o:*:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:1.0.1p:*:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:1.0.1q:*:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:1.0.1r:*:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:1.0.1s:*:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:1.0.1t:*:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:1.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:1.0.2a:*:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:1.0.2b:*:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:1.0.2c:*:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:1.0.2d:*:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:1.0.2e:*:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:1.0.2f:*:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:1.0.2g:*:*:*:*:*:*:*
    • cpe:2.3:a:openssl:openssl:1.0.2h:*:*:*:*:*:*:*
  • cpe:2.3:o:oracle:linux:6:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:oracle:linux:6:*:*:*:*:*:*:*
    • cpe:2.3:o:oracle:linux:7:*:*:*:*:*:*:*
  • cpe:2.3:o:oracle:solaris:10:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:oracle:solaris:10:*:*:*:*:*:*:*
    • cpe:2.3:o:oracle:solaris:11.3:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

26

News mentions

0

No linked articles in our index yet.