The TS_OBJ_print_bio function in crypto/ts/ts_lib.c in the X.509 Public Key Infrastructure Time-Stamp Protocol (TSP) implementation in OpenSSL through 1.0.2h allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted time-stamp file that is mishandled by the "openssl ts" command.
We have discovered 273,254 live websites that are affected by CVE-2016-2180.
| Product | |
| Category | Web Server Extensions |
| Vulnerable Domains | 273,254 live websites (52% of OpenSSL install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 11 versions ( 17% of all versions) |
| 68,275 websites | |
| 22,295 websites | |
| 18,860 websites | |
| 13,532 websites | |
| 12,916 websites | |
| 12,538 websites | |
| 9,509 websites | |
| 8,839 websites | |
| 8,075 websites | |
| 7,999 websites |
| .com | 96,414 websites |
| .net | 12,446 websites |
| .de | 11,400 websites |
| .org | 11,169 websites |
| .nl | 9,793 websites |
| .jp | 8,189 websites |
| .ru | 7,902 websites |
| .it | 6,572 websites |
| .cz | 6,367 websites |
| .co.jp | 4,765 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ****.com | *,*** | ||
| ********.com | *,*** | ||
| *.******.***.***.br | *,*** | ||
| *************.com | *,*** | ||
| *.*****.***.***.br | *,*** | ||
| ****.**.com | *,*** | ||
| *****.org | *,*** | ||
| *****.com | *,*** | ||
| *********.io | *,*** | ||
| *******.in | *,*** |