CVE-2016-6305 describes a denial-of-service vulnerability in OpenSSL versions prior to 1.1.0a, specifically within the ssl3_read_bytes function. This flaw allows remote attackers to trigger an infinite loop by forcing a zero-length record during an SSL_peek call. With a CVSS score of 7.5 (High), it presents a significant risk due to its network-based attack vector and low attack complexity, leading to high availability impact. While no active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB) has been identified, the vulnerability has garnered notable community discussion and media coverage, indicating its perceived importance.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.1.0CPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.