New! Vulnerability Priority Rating (VPR)
Tenable calculates a dynamic VPR for every vulnerability. VPR combines vulnerability information with threat intelligence and machine learning algorithms to predict which vulnerabilities are most likely to be exploited in attacks. Read more about what VPR is and how it's different from CVSS.
VPR Score: 5.9
SynopsisThe remote FreeBSD host is missing one or more security-related updates.
DescriptionOpenSSL reports :
High: OCSP Status Request extension unbounded memory growth
SSL_peek() hang on empty record
OOB write in MDC2_Update()
Malformed SHA512 ticket DoS
OOB write in BN_bn2dec()
OOB read in TS_OBJ_print_bio()
Pointer arithmetic undefined behaviour
Constant time flag not preserved in DSA signing
DTLS buffered message DoS
DTLS replay protection DoS
Certificate message OOB reads
Excessive allocation of memory in tls_get_message_header()
Excessive allocation of memory in dtls1_preprocess_fragment()
NB: LibreSSL is only affected by CVE-2016-6304
SolutionUpdate the affected packages.