CVE-2016-0799: OpenSSL

Critical severity, CVSS 9.8. EPSS: 32.4% chance of exploitation in the next 30 days.

The fmtstr function in crypto/bio/b_print.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g improperly calculates string lengths, which allows remote attackers to cause a denial of service (overflow and out-of-bounds read) or possibly have unspecified other impact via a long string, as demonstrated by a large amount of ASN.1 data, a different vulnerability than CVE-2016-2842.

Affected products

  • OpenSSL OpenSSL: version 1.0.1 only; version 1.0.1a only; version 1.0.1b only; version 1.0.1c only; version 1.0.1d only; version 1.0.1e only; …
  • Pulse Secure Client: affected versions not specified
  • Pulse Secure Steel Belted Radius: affected versions not specified

Published 2016-03-03. Last modified 2026-06-17.