{"id":"CVE-2016-2176","description":"The X509_NAME_oneline function in crypto/x509/x509_obj.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to obtain sensitive information from process stack memory or cause a denial of service (buffer over-read) via crafted EBCDIC ASN.1 data.","cvssScore":8.2,"cvssVersion":"3.0","cvssVector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","cvssMetrics":[{"version":"3.0","score":8.2,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","source":"nvd@nist.gov","sourceName":"NVD","type":"Primary"},{"version":"2.0","score":6.4,"vector":"AV:N/AC:L/Au:N/C:P/I:N/A:P","source":"nvd@nist.gov","sourceName":"NVD","type":"Primary"}],"cwes":["CWE-119"],"resolved":"NOT-APPLICABLE","published":"2016-05-05","lastModified":"2026-06-17","affectedProducts":[{"vendor":"openssl","product":"openssl","versionEnd":"\u003c=1.0.1s"},{"vendor":"openssl","product":"openssl","version":"1.0.2"},{"vendor":"openssl","product":"openssl","version":"1.0.2","update":"beta1"},{"vendor":"openssl","product":"openssl","version":"1.0.2","update":"beta2"},{"vendor":"openssl","product":"openssl","version":"1.0.2","update":"beta3"},{"vendor":"openssl","product":"openssl","version":"1.0.2a"},{"vendor":"openssl","product":"openssl","version":"1.0.2b"},{"vendor":"openssl","product":"openssl","version":"1.0.2c"},{"vendor":"openssl","product":"openssl","version":"1.0.2d"},{"vendor":"openssl","product":"openssl","version":"1.0.2e"},{"vendor":"openssl","product":"openssl","version":"1.0.2f"},{"vendor":"openssl","product":"openssl","version":"1.0.2g"}],"totalAffectedProducts":1,"references":[{"url":"http://lists.apple.com/archives/security-announce/2016/Jul/msg00000.html","source":"secalert@redhat.com"},{"url":"http://packetstormsecurity.com/files/136912/Slackware-Security-Advisory-openssl-Updates.html","source":"secalert@redhat.com"},{"url":"http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160504-openssl","source":"secalert@redhat.com"},{"url":"http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html","source":"secalert@redhat.com"},{"url":"http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html","source":"secalert@redhat.com"},{"url":"http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html","source":"secalert@redhat.com"},{"url":"http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html","source":"secalert@redhat.com"},{"url":"http://www.securityfocus.com/bid/89746","source":"secalert@redhat.com"},{"url":"http://www.securityfocus.com/bid/91787","source":"secalert@redhat.com"},{"url":"http://www.securitytracker.com/id/1035721","source":"secalert@redhat.com"}],"reasoning":{"decidingSource":"h2-history","decidingReason":"Historical classification excluded this CVE and no tracked product appears on the record, so it is not a Java problem ARMR was ever asked to address.","verdicts":[{"rule":"rejected","stage":"identity","outcome":"no-match"},{"rule":"armr-patch-file","stage":"scope","outcome":"no-match"},{"rule":"armr-secure-rule-file","stage":"scope","outcome":"no-match"},{"rule":"manual-classification","stage":"scope","outcome":"no-match"},{"rule":"h2-history","stage":"scope","outcome":"matched","status":"NOT-APPLICABLE","detail":"Found in legacy manual classifications","decisive":true}]},"oracleAdvisories":[{"advisory":"Oracle Critical Patch Update July 2018","releaseType":"CPU","quarter":"2018-Q3","url":"https://www.oracle.com/security-alerts/cpujul2018.html","products":[{"product":"Oracle Communications Applications","component":"Security (OpenSSL)","affectedVersions":"12.x"}]},{"advisory":"Oracle Critical Patch Update April 2017","releaseType":"CPU","quarter":"2017-Q2","url":"https://www.oracle.com/security-alerts/cpuapr2017.html","products":[{"product":"Oracle MySQL","component":"Backup: ENTRBACK (OpenSSL)","affectedVersions":"3.12.2 and earlier, 4.0.1 and earlier"},{"product":"Oracle MySQL","component":"Workbench: Security: Encryption (OpenSSL)","affectedVersions":"6.3.7 and earlier"}]},{"advisory":"Oracle Critical Patch Update October 2016","releaseType":"CPU","quarter":"2016-Q4","url":"https://www.oracle.com/security-alerts/cpuoct2016.html","products":[{"product":"Oracle E-Business Suite","component":"OpenSSL","affectedVersions":"12.1.3"}]}],"assessment":{"record":{"state":"active"},"protection":{"level":"none"},"action":{"state":"not-needed","type":"none"},"review":{"state":"human","basis":"manual-review"}},"h2Comments":"## Manual Classification Context\n\n\n**Labels:** HTTP, MYSQL PROTOCOL, WORKBENCH: SECURITY: ENCRYPTION (OPENSSL), BACKUP: ENTRBACK (OPENSSL), SECURITY (OPENSSL), TLS, NO AUTH REMOTE EXPLOIT, OPENSSL\n\n**Products:** ORACLE E-BUSINESS SUITE, MYSQL WORKBENCH, ORACLE HTTP SERVER, MYSQL ENTERPRISE BACKUP, OPENSSL, ORACLE COMMUNICATIONS APPLICATIONS, ORACLE COMMUNICATIONS POLICY MANAGEMENT, ORACLE MYSQL","signals":{"hasPOC":false,"pocCount":0},"kev":{"inKEV":false},"epss":{"available":true,"score":0.22841,"percentile":0.97605},"ssvc":{"available":false}}