CVE-2016-2177: HP Icewall Mcrp
Critical severity, CVSS 9.8. EPSS: 44.5% chance of exploitation in the next 30 days.
OpenSSL through 1.0.2h incorrectly uses pointer arithmetic for heap-buffer boundary checks, which might allow remote attackers to cause a denial of service (integer overflow and application crash) or possibly have unspecified other impact by leveraging unexpected malloc behavior, related to s3_srvr.c, ssl_sess.c, and t1_lib.c.
Affected products
- HP Icewall Mcrp: version 3.0 only
- HP Icewall SSO: version 10.0 only
- HP Icewall SSO Agent Option: version 10.0 only
- OpenSSL OpenSSL: version 1.0.1 only; version 1.0.1a only; version 1.0.1b only; version 1.0.1c only; version 1.0.1d only; version 1.0.1e only; …
- Oracle Linux: version 5 only; version 6 only; version 7 only
- Oracle Solaris: version 10 only; version 11.3 only
Published 2016-06-20. Last modified 2026-06-17.