CVE-2016-6892 describes a denial-of-service vulnerability in MatrixSSL versions prior to 3.8.6, specifically within the x509FreeExtensions function. A remote attacker can trigger this by providing a specially crafted X.509 certificate, leading to the freeing of unallocated memory. This vulnerability carries a CVSS v3 score of 7.5 (HIGH), indicating it is easily exploitable over the network with no user interaction, resulting in high availability impact. There is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB, though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.8.5CPE matchmatch criteria | cpe:2.3:a:matrixssl:matrixssl:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.