---
cve: "CVE-2016-8610"
severity: "LOW"
cvss: 3.1
epss: "39.7%"
vendor: "OpenSSL"
kev: false
exploited: false
published: "2017-11-13 22:29:00"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-13T17:02:47+02:00"
---

# CVE-2016-8610

> 3.1 LOW

## Beschreibung

A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote attacker could use this flaw to make a TLS/SSL server consume an excessive amount of CPU and fail to accept connections from other clients.

## Referenzen

- <http://www.securityfocus.com/bid/93841>
- <http://rhn.redhat.com/errata/RHSA-2017-1659.html>
- <https://access.redhat.com/errata/RHSA-2017:1658>
- <https://access.redhat.com/errata/RHSA-2017:1801>
- <http://rhn.redhat.com/errata/RHSA-2017-0286.html>
- <https://access.redhat.com/errata/RHSA-2017:1413>
- <https://access.redhat.com/errata/RHSA-2017:2494>
- <https://security.FreeBSD.org/advisories/FreeBSD-SA-16:35.openssl.asc>
- <https://access.redhat.com/errata/RHSA-2017:1414>
- <http://seclists.org/oss-sec/2016/q4/224>
- <http://rhn.redhat.com/errata/RHSA-2017-0574.html>
- <https://www.debian.org/security/2017/dsa-3773>
- <http://rhn.redhat.com/errata/RHSA-2017-1415.html>
- <http://www.securitytracker.com/id/1037084>
- <https://access.redhat.com/errata/RHSA-2017:1802>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2016-8610) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
