Number: AL16-013
Date: 22 June 2016
Purpose
The purpose of this alert is to bring attention to a recently disclosed vulnerability in OpenSSL.
Assessment
CCIRC is aware of a recently disclosed vulnerability in OpenSSL. Identified as CVE-2016-2177, this vulnerability can allow a remote unauthenticated attacker to cause denial of service conditions. Proof-of-concept exploit code has been released publicly.
CVE Reference: CVE-2016-2177
Affected Versions: OpenSSL 1.0.2h and prior
Suggested action
Due to the potential risk presented by this vulnerability, CCIRC recommends that system administrators monitor for the developer released security fix.
References
NIST National Vulnerability Database:
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-2177
OpenSSL:
https://www.openssl.org/