PublicDateAtUSN: 2016-02-22 Candidate: CVE-2016-0705 PublicDate: 2016-03-03 20:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0705 https://www.openssl.org/news/secadv/20160301.txt https://ubuntu.com/security/notices/USN-2914-1 Description: Double free vulnerability in the dsa_priv_decode function in crypto/dsa/dsa_ameth.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a malformed DSA private key. Ubuntu-Description: Notes: Bugs: Priority: low Discovered-by: Adam Langley Assigned-to: mdeslaur CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_openssl: upstream: https://git.openssl.org/?p=openssl.git;a=commit;h=6c88c71b4e4825c7bc0489306d062d017634eb88 (1.0.2) upstream: https://git.openssl.org/?p=openssl.git;a=commit;h=ccb2a614074ee15c0fbbb9dd49e3cd258d68380a (1.0.1) upstream_openssl: needed precise_openssl: released (1.0.1-4ubuntu5.35) trusty_openssl: released (1.0.1f-1ubuntu2.18) trusty/esm_openssl: released (1.0.1f-1ubuntu2.18) vivid/ubuntu-core_openssl: released (1.0.1f-1ubuntu11.6) vivid/stable-phone-overlay_openssl: released (1.0.1f-1ubuntu11.6) wily_openssl: released (1.0.2d-0ubuntu1.4) xenial_openssl: released (1.0.2g-1ubuntu2) esm-infra/xenial_openssl: released (1.0.2g-1ubuntu2) devel_openssl: released (1.0.2g-1ubuntu2) Patches_openssl098: upstream_openssl098: needed precise_openssl098: not-affected (code not present) trusty_openssl098: not-affected (code not present) trusty/esm_openssl098: DNE (trusty was not-affected [code not present]) vivid/ubuntu-core_openssl098: DNE vivid/stable-phone-overlay_openssl098: DNE wily_openssl098: DNE xenial_openssl098: DNE devel_openssl098: DNE