header

Denial of Service (DoS) Vulnerability in OpenSSL (CVE-2016-2177)


Mar 10, 2023
Share

Denial of Service (DoS) Vulnerability in OpenSSL (CVE-2016-2177)

Summary

This issue has been resolved as of Firmware 4.80.

Vulnerability ID Vulnerability Overview
CVE-2016-2177 OpenSSL through 1.0.2h incorrectly uses pointer arithmetic for heap-buffer boundary checks, which might allow remote attackers to cause a denial of service (integer overflow and application crash) or possibly have unspecified other impact by leveraging unexpected malloc behavior, related to s3_srvr.c, ssl_sess.c, and t1_lib.c.

Affected Supported TeraStations

TS6000
TS5020/TS5010
TS3020/TS3010

Back to Security Notices

Date Description
3/10/2022 Initial release
X