CVE-2016-0797

Source
https://cve.org/CVERecord?id=CVE-2016-0797
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-0797.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2016-0797
Downstream
Related
Published
2016-03-03T20:59:01.813Z
Modified
2026-02-11T08:21:24.455812Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

Multiple integer overflows in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g allow remote attackers to cause a denial of service (heap memory corruption or NULL pointer dereference) or possibly have unspecified other impact via a long digit string that is mishandled by the (1) BNdec2bn or (2) BNhex2bn function, related to crypto/bn/bn.h and crypto/bn/bn_print.c.

References

Affected packages

Git / github.com/nodejs/node

Affected versions

v4.*
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.2.5
v4.2.6
v4.3.0
v4.3.1
v5.*
v5.0.0
v5.1.0
v5.1.1
v5.2.0
v5.3.0
v5.4.0
v5.4.1
v5.5.0
v5.6.0
v5.7.0

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-0797.json"