CVE-2016-7053 is a high-severity NULL pointer dereference vulnerability affecting OpenSSL versions prior to 1.1.0c. This flaw occurs when applications parse invalid CMS structures due to a bug in handling ASN.1 CHOICE types, leading to a crash. The vulnerability has a CVSS v3 score of 7.5, indicating a network-based attack with low complexity, requiring no user interaction, and resulting in high availability impact (denial of service). There is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.1.0CPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.1.0:*:*:*:*:*:*:* | ||
1.1.0aCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.1.0a:*:*:*:*:*:*:* | ||
1.1.0bCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.1.0b:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.