Candidate: CVE-2016-2176 CRD: 2016-05-03 PublicDate: 2016-05-05 01:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2176 https://www.openssl.org/news/secadv/20160503.txt Description: The X509_NAME_oneline function in crypto/x509/x509_obj.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to obtain sensitive information from process stack memory or cause a denial of service (buffer over-read) via crafted EBCDIC ASN.1 data. Ubuntu-Description: Notes: mdeslaur> only affects EBCDIC systems, not relevant for Ubuntu Bugs: Priority: negligible Discovered-by: Guido Vranken Assigned-to: mdeslaur CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H [8.2 HIGH] Patches_openssl: upstream_openssl: released (1.0.1o, 1.0.2c) precise_openssl: not-affected trusty_openssl: not-affected trusty/esm_openssl: not-affected vivid/ubuntu-core_openssl: not-affected vivid/stable-phone-overlay_openssl: not-affected wily_openssl: not-affected xenial_openssl: not-affected esm-infra/xenial_openssl: not-affected devel_openssl: not-affected Patches_openssl098: upstream_openssl098: needs-triage precise_openssl098: not-affected trusty_openssl098: not-affected trusty/esm_openssl098: DNE (trusty was not-affected) vivid/ubuntu-core_openssl098: DNE vivid/stable-phone-overlay_openssl098: DNE wily_openssl098: DNE xenial_openssl098: DNE devel_openssl098: DNE