CVE-2016-6884
medium
CVSS v3
6.5
CVSS v2
4.3
VIR risk
6.5
Description
TLS cipher suites with CBC mode in TLS 1.1 and 1.2 in MatrixSSL before 3.8.3 allow remote attackers to cause a denial of service (out-of-bounds read) via a crafted message.
Predictions
Exploit likelihood
75%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cve@mitre.org — https://github.com/matrixssl/matrixssl/blob/master/CHANGES.md
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| matrixssl | matrixssl | {"endIncluding":"3.8.2"} | |
References
- http://www.openwall.com/lists/oss-security/2016/08/19/8
- http://www.securityfocus.com/bid/91488
- https://github.com/matrixssl/matrixssl/blob/master/CHANGES.md
- http://www.openwall.com/lists/oss-security/2016/08/19/8
- http://www.securityfocus.com/bid/91488
- https://github.com/matrixssl/matrixssl/blob/master/CHANGES.md
CWEs
CWE-125
Verify integrity in audit chain (admin only). AS-IS.