suse · CVE-2016-7052

Quick triage

Priority: high 公開: 2021-05-30 13:45:16 UTC Updated: 2026-04-18 16:02:32 UTC

参照: Official suse advisory, NVD, CVE.org · CVE 詳細

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2016-7052 severity important: SUSE including 494 source package names (MozillaFirefox-68.2.0-78.51.4, MozillaFirefox-branding-SLED-68-21.9.8, …), 893 product×package rows across 91 product lines (HPE Helion OpenStack 8, SUSE CaaS Platform 4.0, … (91 product lines)): Fixed 475, Known Not Affected 261, Known Affected 157.

Description:

crypto/x509/x509_vfy.c in OpenSSL 1.0.2i allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by triggering a CRL operation.

cvelogic Threat Intelligence