CVE-2016-6304
Description
Multiple memory leaks in t1_lib.c in OpenSSL before 1.0.1u, 1.0.2 before 1.0.2i, and 1.1.0 before 1.1.0a allow remote attackers to cause a denial of service (memory consumption) via large OCSP Status Request extensions.
Risk Information
Base Score
7.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
23.429
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Multiple vulnerabilities fixed in OpenSSL (x64) 1.0.1u | Windows |
| Multiple vulnerabilities fixed in OpenSSL (x64) 1.0.2i | Windows |
| Vulnerabilities CVE-2016-6305,CVE-2016-6304,CVE-2016-6308,CVE-2016-6307 are fixed in OpenSSL (x64) 1.1.0a | Windows |
| Multiple vulnerabilities affected in Mysql 5.6.21 | Windows |
| Multiple vulnerabilities affected in Mysql 5.6.22 | Windows |
| Multiple vulnerabilities affected in Mysql 5.6.23 | Windows |
| Multiple vulnerabilities affected in Mysql 5.6.24 | Windows |
| Multiple vulnerabilities affected in Mysql 5.6.25 | Windows |
| Multiple vulnerabilities affected in Mysql 5.6.26 | Windows |
| Multiple vulnerabilities affected in Mysql 5.6.35 | Windows |
| Multiple vulnerabilities affected in Mysql 5.6.9 | Windows |
| Multiple vulnerabilities are fixed in Nessus 6.9 | Windows |
| Multiple vulnerabilities are fixed in Tenable Nessus 6.9 | Windows |
| Vulnerabilities CVE-2016-5584,CVE-2016-6304,CVE-2016-6662,CVE-2016-7440 are affected in Mysql earlier | Windows |
| Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 5.2 | Windows |
| Multiple Vulnerabilities are affected in IBM Cognos Controller 10.2.0 | Windows |
| Multiple Vulnerabilities are affected in IBM Cognos Controller 10.2.1 | Windows |
| Multiple Vulnerabilities are affected in IBM Cognos Controller 10.1.1 | Windows |
| Multiple Vulnerabilities are affected in IBM Cognos Controller 10.1.0 | Windows |
| Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.0.5.0 | Windows |
| (RHSA-2016:2802) Important: openssl security update openssl-1.0.0-27.el6_4.6.i686.rpm | Linux |
| (RHSA-2016:2802) Important: openssl security update openssl-devel-1.0.0-27.el6_4.6.i686.rpm | Linux |
| (RHSA-2016:2802) Important: openssl security update openssl-perl-1.0.0-27.el6_4.6.x86_64.rpm | Linux |
| (RHSA-2016:2802) Important: openssl security update openssl-static-1.0.0-27.el6_4.6.x86_64.rpm | Linux |
| Multiple vulnerabilities affected in Mysql 5.6.21 (For Linux) | Linux |
| Multiple vulnerabilities affected in Mysql 5.6.22 (For Linux) | Linux |
| Multiple vulnerabilities affected in Mysql 5.6.23 (For Linux) | Linux |
| Multiple vulnerabilities affected in Mysql 5.6.24 (For Linux) | Linux |
| Multiple vulnerabilities affected in Mysql 5.6.25 (For Linux) | Linux |
| Multiple vulnerabilities affected in Mysql 5.6.26 (For Linux) | Linux |
| Multiple vulnerabilities affected in Mysql 5.6.35 (For Linux) | Linux |
| Multiple vulnerabilities affected in Mysql 5.6.9 (For Linux) | Linux |
| (CESA-2016:2802) Important: openssl security update openssl-1.0.0-27.el6_4.6.i686.rpm | Linux |
| (CESA-2016:2802) Important: openssl security update openssl-devel-1.0.0-27.el6_4.6.i686.rpm | Linux |
| (CESA-2016:2802) Important: openssl security update openssl-perl-1.0.0-27.el6_4.6.x86_64.rpm | Linux |
| (CESA-2016:2802) Important: openssl security update openssl-static-1.0.0-27.el6_4.6.x86_64.rpm | Linux |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Adaptive Security Appliance (ASA) Software | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco AnyConnect Secure Mobility Client | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Application and Content Networking System (ACNS) Software | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Digital Content Manager (DCM) Software | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Emergency Responder | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco IP Phone 7800 Series | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Jabber for Mac | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Jabber for Windows | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Jabber Guest | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Jabber Software Development Kit | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco MediaSense | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Paging Server | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Plug-in for OpenFlow | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Prime Infrastructure | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Prime Network Services Controller | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco TelePresence ISDN Link | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco TelePresence Serial Gateway Series | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco UCS Director | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Unified Contact Center Enterprise | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Unified Intelligence Center | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Unified MeetingPlace | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Unified SIP Proxy | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Unity Connection | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Unity Express | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Video Surveillance 6000 Series IP Cameras | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco ASR 5000 Series | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco IronPort Encryption Appliance Software | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Firepower Management Center Virtual Appliance | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco IronPort Security Management Appliance Software | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Data Center Network Manager | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Intercloud Fabric | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Nexus 1000V Switch for VMware vSphere | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For CiscoPro Workgroup EtherSwitch Software | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Unified Computing System | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco UCS Central Software | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco ASR 1000 Series Aggregation Services Routers | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Cloud Services Router 1000V Series | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco 4000 Series Integrated Services Routers | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco 1000 Series Integrated Services Routers | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For CiscoWorks Common Services Software | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Wireless Network Management Software Suite | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Prime Collaboration | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Virtual Wireless Controller | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Network Convergence System 540 Series Routers | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Digital Media Manager | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Video Networking Solutions | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco TelePresence ISDN Gateway | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco TelePresence MCU 4500 Series | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco TelePresence MSE 8000 Series | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco MXE 3000 Series (Media Experience Engines) | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Unified Communications Licensing | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco TelePresence Content Server | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco TelePresence Server | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco TelePresence Video Communication Server Software | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco IPICS Server Software | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Conductor | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Enterprise CDN Software | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco NAC Appliance (Clean Access) | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco NAC Appliance 3300 Series | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Wide Area Application Services (WAAS) Appliances | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Support Tools | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco ONS 15454 Series Multiservice Provisioning Platforms | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Video Surveillance 4000 Series IP Cameras | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Video Surveillance Manager | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Identity Services Engine | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Small Business Voice Gateways and ATAs | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco IPS 4200 Series Sensors | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco 1000 Series Connected Grid Routers | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Unified Attendant Consoles | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Unified Communications Manager (CallManager) | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Hosted Collaboration Solution (HCS) | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Jabber for iPhone | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco SIP IP Phone Software | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco IP Phone 8800 Series | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco IP Phone FW 7900 Series Software | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Unified Mobile Communicator | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Telepresence Integrator C Series | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For | NCM |
| Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Policy Suite for Mobile | NCM |
| Missing Release of Memory after Effective Lifetime Vulnerability (CVE-2016-6304) | NCM |
Patch Details
Click to see the patches provided by ManageEngine for this CVE
| Patch ID | Patch Description |
|---|---|
| PATCH-1706057 | Security Update for Cisco Adaptive Security Appliance (ASA) Software 99.17(1.69) |
| PATCH-1705981 | Security Update for Cisco AnyConnect Secure Mobility Client 4.3(2034) |
| PATCH-1705634 | Security Update for Cisco Application and Content Networking System (ACNS) Software 3.0(0)A5(3.1a) |
| PATCH-1706007 | Security Update for Cisco Digital Content Manager (DCM) Software 20.0.0 |
| PATCH-1706049 | Security Update for Cisco Emergency Responder 12.0(0.98000.50) |
| PATCH-1705975 | Security Update for Cisco IP Phone 7800 Series 11.7(1) |
| PATCH-1705811 | Security Update for Cisco Jabber for Windows 11.6(1.38147) |
| PATCH-1705783 | Security Update for Cisco Jabber Guest 10.6(11) |
| PATCH-1706051 | Security Update for Cisco Jabber Software Development Kit 11.8(2) |
| PATCH-1705879 | Security Update for Cisco MediaSense 11.5(1.10000.6) |
| PATCH-1706011 | Security Update for Cisco Paging Server 12.0(1) |
| PATCH-1701673 | Security Update for Cisco Plug-in for OpenFlow 4.12(0)SP1 |
| PATCH-1705595 | Security Update for Cisco Prime Infrastructure 2.2(2) |
| PATCH-1701930 | Security Update for Cisco Prime Network Services Controller 21.2.A0.65491 |
| PATCH-1705893 | Security Update for Cisco TelePresence ISDN Link IL1.1.7 |
| PATCH-1705959 | Security Update for Cisco TelePresence Serial Gateway Series 1.0(1.52) |
| PATCH-1705947 | Security Update for Cisco UCS Director 6.0(1.0) |
| PATCH-1705943 | Security Update for Cisco Unified Contact Center Enterprise 11.6(1)SR0(0) |
| PATCH-1705886 | Security Update for Cisco Unified Intelligence Center 11.5(0.98000.126) |
| PATCH-1705973 | Security Update for Cisco Unified MeetingPlace 8.6(2.45) |
| PATCH-1705497 | Security Update for Cisco Unified SIP Proxy 8.5(5) |
| PATCH-1706048 | Security Update for Cisco Unity Connection 12.0(0.97000.184) |
| PATCH-1703070 | Security Update for Cisco Unity Express 6.2.1 |
| PATCH-1705965 | Security Update for Cisco Video Surveillance 6000 Series IP Cameras 2.9 |
| PATCH-1706032 | Security Update for Cisco ASR 5000 Series 21.3.A0.66703 |
| PATCH-1705938 | Security Update for Cisco Firepower Management Center Virtual Appliance 6.1.0.1 |
| PATCH-1706033 | Security Update for Cisco IronPort Security Management Appliance Software 11.0.1-152 |
| PATCH-1706034 | Security Update for Cisco Data Center Network Manager 10.1(1.158)S0 |
| PATCH-1705855 | Security Update for Cisco Intercloud Fabric 3.3(1) |
| PATCH-1705949 | Security Update for Cisco Nexus 1000V Switch for VMware vSphere 5.2(1)SV3(3.1) |
| PATCH-1706035 | Security Update for CiscoPro Workgroup EtherSwitch Software 6.0(2)A8(4) |
| PATCH-1706036 | Security Update for Cisco Unified Computing System 3.2(1d) |
| PATCH-1705950 | Security Update for Cisco UCS Central Software 2.0(1a) |
| PATCH-1705898 | Security Update for Cisco ASR 1000 Series Aggregation Services Routers Denali-16.3.4a |
| PATCH-1705899 | Security Update for Cisco Cloud Services Router 1000V Series Denali-16.3.4a |
| PATCH-1705901 | Security Update for Cisco 4000 Series Integrated Services Routers Denali-16.3.4a |
| PATCH-1705902 | Security Update for Cisco 1000 Series Integrated Services Routers Denali-16.3.4a |
| PATCH-1705477 | Security Update for CiscoWorks Common Services Software 4.2(4) |
| PATCH-1705952 | Security Update for Cisco Wireless Network Management Software Suite 8.0(150) |
| PATCH-1705997 | Security Update for Cisco Prime Collaboration 11.0(0.815) |
| PATCH-1705937 | Security Update for Cisco Virtual Wireless Controller 8.3(15.155) |
| PATCH-1706041 | Security Update for Cisco Network Convergence System 540 Series Routers 6.4.1.8i.BASE |
| PATCH-1705797 | Security Update for Cisco Digital Media Manager 5.6.3 |
| PATCH-1705954 | Security Update for Cisco Video Networking Solutions 2.6.9 |
| PATCH-1705955 | Security Update for Cisco TelePresence ISDN Gateway 2.2(1.122) |
| PATCH-1705864 | Security Update for Cisco TelePresence MCU 4500 Series 4.5(1.89) |
| PATCH-1705956 | Security Update for Cisco TelePresence MSE 8000 Series 2.3(1.51) |
| PATCH-1705957 | Security Update for Cisco MXE 3000 Series (Media Experience Engines) 3.5.2 |
| PATCH-1706042 | Security Update for Cisco Unified Communications Licensing 11.5(1.12001.2) |
| PATCH-1705866 | Security Update for Cisco TelePresence Content Server 7.2 |
| PATCH-1705960 | Security Update for Cisco TelePresence Server 4.4(1.16) |
| PATCH-1706044 | Security Update for Cisco TelePresence Video Communication Server Software X8.9.2 |
| PATCH-1705988 | Security Update for Cisco IPICS Server Software 4.10(2) |
| PATCH-1705867 | Security Update for Cisco Conductor 3.600 |
| PATCH-1705827 | Security Update for Cisco Enterprise CDN Software 5.5(41.2) |
| PATCH-1705725 | Security Update for Cisco NAC Appliance (Clean Access) 4.9(5) |
| PATCH-1706001 | Security Update for Cisco Wide Area Application Services (WAAS) Appliances 6.3(0.185) |
| PATCH-1705963 | Security Update for Cisco ONS 15454 Series Multiservice Provisioning Platforms 10.6(2) |
| PATCH-1705964 | Security Update for Cisco Video Surveillance 4000 Series IP Cameras 2.4(6.310) |
| PATCH-1706045 | Security Update for Cisco Video Surveillance Manager 7.10 |
| PATCH-1706002 | Security Update for Cisco Identity Services Engine 2.0(0.905) |
| PATCH-1702213 | Security Update for Cisco Small Business Voice Gateways and ATAs 7.6.2SR5 |
| PATCH-1705754 | Security Update for Cisco IPS 4200 Series Sensors 7.3(5)P1 |
| PATCH-1705873 | Security Update for Cisco 1000 Series Connected Grid Routers 15.6(3.0q)M |
| PATCH-1706047 | Security Update for Cisco Unified Attendant Consoles 11.0(2) |
| PATCH-1706016 | Security Update for Cisco Unified Communications Manager (CallManager) CUP.11.5(1.12900.25) |
| PATCH-1706050 | Security Update for Cisco Hosted Collaboration Solution (HCS) 11.5(1.93540.24) |
| PATCH-1705972 | Security Update for Cisco Jabber for iPhone 11.8(1.250291) |
| PATCH-1705918 | Security Update for Cisco SIP IP Phone Software 11.7(1)MN19 |
| PATCH-1705974 | Security Update for Cisco IP Phone 8800 Series 11.7(1)SC2 |
| PATCH-1705386 | Security Update for Cisco IP Phone FW 7900 Series Software 9.4(2)TH1.1 |
| PATCH-1705976 | Security Update for Cisco Unified Mobile Communicator 11.8(1.250274) |
| PATCH-1706043 | Security Update for Cisco Telepresence Integrator C Series 9.1.1 |
| PATCH-1706026 | Security Update for CAF-1.2.0.0 |
| PATCH-1705812 | Security Update for Cisco Policy Suite for Mobile 8.1.0 |
References
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234