CVE-2016-0798 is a memory leak vulnerability in OpenSSL versions 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g, specifically within the SRP_VBASE_get_by_user implementation. A remote attacker can trigger this by providing an invalid username during a connection attempt, leading to a denial of service through memory consumption. Rated with a CVSS score of 7.5 (HIGH), this vulnerability is network-exploitable with low attack complexity and can result in high availability impact. While it garnered significant media coverage and community discussion at the time, there is no evidence of active exploitation, nor are there publicly available exploits in common frameworks like Metasploit or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.1CPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.1:*:*:*:*:*:*:* | ||
1.0.1CPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.1:beta1:*:*:*:*:*:* | ||
1.0.1CPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.1:beta2:*:*:*:*:*:* | ||
1.0.1CPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.1:beta3:*:*:*:*:*:* | ||
1.0.1aCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.1a:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.