The TSOBJprintbio function in crypto/ts/tslib.c in the X.509 Public Key Infrastructure Time-Stamp Protocol (TSP) implementation in OpenSSL through 1.0.2h allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted time-stamp file that is mishandled by the "openssl ts" command.
{
"unresolved_ranges": [
{
"extracted_events": [
{
"last_affected": "6"
},
{
"last_affected": "7"
}
],
"cpes": [
"cpe:2.3:o:oracle:linux:6:*:*:*:*:*:*:*",
"cpe:2.3:o:oracle:linux:7:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:linux",
"source": "CPE_FIELD"
}
]
}