CVE-2016-0799 is a critical vulnerability in OpenSSL versions 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g, affecting the fmtstr function in crypto/bio/b_print.c. It improperly calculates string lengths, leading to an overflow and out-of-bounds read when processing long strings, such as large ASN.1 data. This flaw impacts OpenSSL clients and servers, as well as Pulse Secure products utilizing these OpenSSL versions. Rated with a CVSS score of 9.8 (CRITICAL), this vulnerability is remotely exploitable with low attack complexity and no user interaction required. Successful exploitation can result in a denial of service, with potential for high impact on confidentiality, integrity, and availability. The EPSS score indicates a high likelihood of exploitation. Currently, there is no public exploit code available on Metasploit, Nuclei, or ExploitDB, and it is not listed in the CISA KEV catalog. Despite this, the vulnerability has garnered significant community discussion and media coverage, including an article from SecurityWeek, indicating its perceived importance.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.1CPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.1:*:*:*:*:*:*:* | ||
1.0.1CPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.1:beta1:*:*:*:*:*:* | ||
1.0.1CPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.1:beta2:*:*:*:*:*:* | ||
1.0.1CPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.1:beta3:*:*:*:*:*:* | ||
1.0.1aCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.1a:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.