{"id":66242,"date":"2016-12-13T17:13:40","date_gmt":"2016-12-14T01:13:40","guid":{"rendered":"https:\/\/securingtomorrow.mcafee.com\/?p=66242"},"modified":"2025-06-06T01:03:21","modified_gmt":"2025-06-06T08:03:21","slug":"ssl-death-alert-cve-2016-8610-can-cause-denial-of-service-to-openssl-servers","status":"publish","type":"post","link":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ssl-death-alert-cve-2016-8610-can-cause-denial-of-service-to-openssl-servers\/","title":{"rendered":"&#8216;SSL Death Alert&#8217; (CVE-2016-8610) Can Cause Denial of Service to OpenSSL Servers"},"content":{"rendered":"<p>Recently we noticed <a href=\"https:\/\/git.openssl.org\/gitweb\/?p=openssl.git;a=commit;h=af58be768ebb690f78530f796e92b8ae5c9a4401\">a security patch<\/a> has been published for the OpenSSL vulnerability called SSL Death Alert. As with other serious security vulnerabilities, this one grabbed our attention because the discover er of the vulnerability says that it may cause a denial of service to an OpenSSL web server. To better protect our customers from this attack and provide detection and prevention for this vulnerability, the McAfee Labs IPS Vulnerability Research team looked into this issue.<\/p>\n<p>Our analysis started with the patch differences report of the newly pushed code.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-67088 size-full\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-1.png\" alt=\"2016-12-13-openssl-death-alert-1\" width=\"794\" height=\"435\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-1.png 794w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-1-300x164.png 300w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-1-768x421.png 768w\" sizes=\"auto, (max-width: 794px) 100vw, 794px\" \/><\/p>\n<p>As we can see in the diffing results, a couple of files have been modified to fix this problem.<\/p>\n<p>The patch diff of include\/openssl\/ssl.h reveals the new error code SSL_R_TOO_MANY_WARN_ALERTS (409) has been introduced.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-67087 size-full\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-2.png\" alt=\"2016-12-13-openssl-death-alert-2\" width=\"699\" height=\"342\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-2.png 699w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-2-300x147.png 300w\" sizes=\"auto, (max-width: 699px) 100vw, 699px\" \/><\/p>\n<p>In ssl\/record\/record_locl.h, we can see the directive MAX_WARN_ALERT_COUNT has been introduced and is set to 5.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-67086 size-full\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-3.png\" alt=\"2016-12-13-openssl-death-alert-3\" width=\"903\" height=\"470\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-3.png 903w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-3-300x156.png 300w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-3-768x400.png 768w\" sizes=\"auto, (max-width: 903px) 100vw, 903px\" \/><\/p>\n<p>Now let\u2019s look into the actual patch, which sits in the files ssl\/record\/rec_layer_d1.c and ssl\/record\/rec_layer_s3.c.<\/p>\n<p>The following screen shots show the patch changes in the two files.<\/p>\n<p><strong><u>ssl\/record\/rec_layer_d1.c<\/u><\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-67085 size-full\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-4.png\" alt=\"2016-12-13-openssl-death-alert-4\" width=\"994\" height=\"746\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-4.png 994w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-4-300x225.png 300w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-4-768x576.png 768w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-4-666x500.png 666w\" sizes=\"auto, (max-width: 994px) 100vw, 994px\" \/><\/p>\n<p><strong><u>ssl\/record\/rec_layer_s3.c<\/u><\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-67084 size-full\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-5.png\" alt=\"2016-12-13-openssl-death-alert-5\" width=\"1034\" height=\"756\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-5.png 1034w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-5-300x219.png 300w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-5-768x562.png 768w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-5-1024x749.png 1024w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-5-684x500.png 684w\" sizes=\"auto, (max-width: 1034px) 100vw, 1034px\" \/><\/p>\n<p>As we can see, the patch is pretty simple and straightforward. It simply counts the layers of consecutive SSL3_AL_WARNING alert packets and checks if the count exceeds five. If the count is greater than five, it raises an error.<\/p>\n<h2><strong><u>Exploiting this issue<\/u><\/strong><\/h2>\n<p>To provide detection and prevention for this DoS attack, we created a minimal proof of concept. Although there is no public exploit, <a href=\"http:\/\/seclists.org\/oss-sec\/2016\/q4\/224\">the advisory<\/a> provides a lot of technical details. To exploit this bug, we must initiate the SSL handshake. As a part of the handshake the attacker has to send a genuine Client Hello packet to the server. The following screen shot shows a packet capture of the first stage of the exploit, a normal Client Hello packet.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-67083 size-full\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-6.png\" alt=\"2016-12-13-openssl-death-alert-6\" width=\"760\" height=\"80\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-6.png 760w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-6-300x32.png 300w\" sizes=\"auto, (max-width: 760px) 100vw, 760px\" \/><\/p>\n<p>As described in the security advisory, to exhaust the CPU, we need to send a large number of crafted cleartext SSL3_AL_WARNING alert packets to the server. To do this, we must understand the structure of an alert packet. The message looks like the following, from <a href=\"https:\/\/tools.ietf.org\/html\/rfc5246#page-29\">this TLS protocol memo.<\/a><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-67082 size-full\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-7.png\" alt=\"2016-12-13-openssl-death-alert-7\" width=\"399\" height=\"94\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-7.png 399w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-7-300x71.png 300w\" sizes=\"auto, (max-width: 399px) 100vw, 399px\" \/><\/p>\n<p>An alert message can be encrypted, but in this case we have to send a cleartext alert to the vulnerable server.<\/p>\n<p>The following screen shot shows captured SSL3_AL_WARNING packets in our test environment.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-67081 size-full\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-8.png\" alt=\"2016-12-13-openssl-death-alert-8\" width=\"783\" height=\"312\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-8.png 783w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-8-300x120.png 300w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-8-768x306.png 768w\" sizes=\"auto, (max-width: 783px) 100vw, 783px\" \/><\/p>\n<p>Next we see multiple alerts packed inside a single record.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-67080 size-full\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-9.png\" alt=\"2016-12-13-openssl-death-alert-9\" width=\"383\" height=\"323\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-9.png 383w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-9-300x253.png 300w\" sizes=\"auto, (max-width: 383px) 100vw, 383px\" \/><\/p>\n<p>The alert packet structure looks like this:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-67079 size-full\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-10.png\" alt=\"2016-12-13-openssl-death-alert-10\" width=\"694\" height=\"171\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-10.png 694w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-10-300x74.png 300w\" sizes=\"auto, (max-width: 694px) 100vw, 694px\" \/><\/p>\n<p>To test the developed exploit, we configured a test server with OpenSSL and self-signed certificate and private key. The following screen shot shows the server listening to port 4433 and communicating with an SSL client.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-67078 size-full\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-11.png\" alt=\"2016-12-13-openssl-death-alert-11\" width=\"1425\" height=\"816\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-11.png 1425w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-11-300x172.png 300w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-11-768x440.png 768w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-11-1024x586.png 1024w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-11-873x500.png 873w\" sizes=\"auto, (max-width: 1425px) 100vw, 1425px\" \/><\/p>\n<p>During normal SSL communications between server and client, we see nothing abnormal with CPU consumption of server processes.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-67077 size-full\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-12.png\" alt=\"2016-12-13-openssl-death-alert-12\" width=\"1022\" height=\"212\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-12.png 1022w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-12-300x62.png 300w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-12-768x159.png 768w\" sizes=\"auto, (max-width: 1022px) 100vw, 1022px\" \/><\/p>\n<p>As soon as we run the exploit against the server, however, we immediately see the server process stops responding as CPU usage reaches 99% and then 100% after a few seconds.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-67076 size-full\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-13.png\" alt=\"2016-12-13-openssl-death-alert-13\" width=\"969\" height=\"89\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-13.png 969w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-13-300x28.png 300w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-13-768x71.png 768w\" sizes=\"auto, (max-width: 969px) 100vw, 969px\" \/><\/p>\n<p>The CPU spike causes a denial of service by the OpenSSL Server as it becomes inaccessible. In our test environment, we noticed the SSL service resumes as soon as we stop the exploit from sending malicious packets.<\/p>\n<p>Server administrators should apply <a href=\"https:\/\/git.openssl.org\/gitweb\/?p=openssl.git;a=patch;h=af58be768ebb690f78530f796e92b8ae5c9a4401\">the patch<\/a> to OpenSSL servers as soon as possible. McAfee Network Security Platform (IPS) signature 0x45c09000 provides detection and prevention for this attack.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Recently we noticed a security patch has been published for the OpenSSL vulnerability called SSL Death Alert. As with other&#8230;<\/p>\n","protected":false},"author":674,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[442],"tags":[4850,4827],"coauthors":[3973],"class_list":["post-66242","post","type-post","status-publish","format-standard","hentry","category-mcafee-labs","tag-virtual-patching","tag-vulnerability"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v25.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>&#039;SSL Death Alert&#039; (CVE-2016-8610) Can Cause Denial of Service to OpenSSL Servers | McAfee Blog<\/title>\n<meta name=\"description\" content=\"Recently we noticed a security patch has been published for the OpenSSL vulnerability called SSL Death Alert. As with other serious security\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"&#039;SSL Death Alert&#039; (CVE-2016-8610) Can Cause Denial of Service to OpenSSL Servers | McAfee Blog\" \/>\n<meta property=\"og:description\" content=\"Recently we noticed a security patch has been published for the OpenSSL vulnerability called SSL Death Alert. As with other serious security\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ssl-death-alert-cve-2016-8610-can-cause-denial-of-service-to-openssl-servers\/\" \/>\n<meta property=\"og:site_name\" content=\"McAfee Blog\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/McAfee\/\" \/>\n<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/McAfee\/\" \/>\n<meta property=\"article:published_time\" content=\"2016-12-14T01:13:40+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-06-06T08:03:21+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-1.png\" \/>\n\t<meta property=\"og:image:width\" content=\"794\" \/>\n\t<meta property=\"og:image:height\" content=\"435\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"McAfee\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@McAfee\" \/>\n<meta name=\"twitter:site\" content=\"@McAfee\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"McAfee\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ssl-death-alert-cve-2016-8610-can-cause-denial-of-service-to-openssl-servers\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ssl-death-alert-cve-2016-8610-can-cause-denial-of-service-to-openssl-servers\/\"},\"author\":{\"name\":\"McAfee\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/47851fdb92fad9456152405839c92efa\"},\"headline\":\"&#8216;SSL Death Alert&#8217; (CVE-2016-8610) Can Cause Denial of Service to OpenSSL Servers\",\"datePublished\":\"2016-12-14T01:13:40+00:00\",\"dateModified\":\"2025-06-06T08:03:21+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ssl-death-alert-cve-2016-8610-can-cause-denial-of-service-to-openssl-servers\/\"},\"wordCount\":587,\"publisher\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ssl-death-alert-cve-2016-8610-can-cause-denial-of-service-to-openssl-servers\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-1.png\",\"keywords\":[\"virtual patching\",\"vulnerability\"],\"articleSection\":[\"McAfee Labs\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ssl-death-alert-cve-2016-8610-can-cause-denial-of-service-to-openssl-servers\/\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ssl-death-alert-cve-2016-8610-can-cause-denial-of-service-to-openssl-servers\/\",\"name\":\"'SSL Death Alert' (CVE-2016-8610) Can Cause Denial of Service to OpenSSL Servers | McAfee Blog\",\"isPartOf\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ssl-death-alert-cve-2016-8610-can-cause-denial-of-service-to-openssl-servers\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ssl-death-alert-cve-2016-8610-can-cause-denial-of-service-to-openssl-servers\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-1.png\",\"datePublished\":\"2016-12-14T01:13:40+00:00\",\"dateModified\":\"2025-06-06T08:03:21+00:00\",\"description\":\"Recently we noticed a security patch has been published for the OpenSSL vulnerability called SSL Death Alert. As with other serious security\",\"breadcrumb\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ssl-death-alert-cve-2016-8610-can-cause-denial-of-service-to-openssl-servers\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ssl-death-alert-cve-2016-8610-can-cause-denial-of-service-to-openssl-servers\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ssl-death-alert-cve-2016-8610-can-cause-denial-of-service-to-openssl-servers\/#primaryimage\",\"url\":\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-1.png\",\"contentUrl\":\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-1.png\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ssl-death-alert-cve-2016-8610-can-cause-denial-of-service-to-openssl-servers\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Blog\",\"item\":\"https:\/\/www.mcafee.com\/blogs\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Other Blogs\",\"item\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"McAfee Labs\",\"item\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/\"},{\"@type\":\"ListItem\",\"position\":4,\"name\":\"&#8216;SSL Death Alert&#8217; (CVE-2016-8610) Can Cause Denial of Service to OpenSSL Servers\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#website\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/\",\"name\":\"McAfee Blog\",\"description\":\"Internet Security News\",\"publisher\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.mcafee.com\/blogs\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#organization\",\"name\":\"McAfee\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/02\/mcafee-logo.png\",\"contentUrl\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/02\/mcafee-logo.png\",\"width\":1286,\"height\":336,\"caption\":\"McAfee\"},\"image\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/McAfee\/\",\"https:\/\/x.com\/McAfee\",\"https:\/\/www.linkedin.com\/company\/mcafee\/\",\"https:\/\/www.youtube.com\/McAfee\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/47851fdb92fad9456152405839c92efa\",\"name\":\"McAfee\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/image\/1ffadfeeda1f4f9e7891a81f27a9ecf4\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2020\/08\/Original-Logo-96x96.png\",\"contentUrl\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2020\/08\/Original-Logo-96x96.png\",\"caption\":\"McAfee\"},\"description\":\"We're here to make life online safe and enjoyable for everyone.\",\"sameAs\":[\"https:\/\/www.facebook.com\/McAfee\/\",\"https:\/\/www.linkedin.com\/company\/mcafee\/\",\"https:\/\/x.com\/McAfee\"],\"url\":\"https:\/\/www.mcafee.com\/blogs\/author\/mcafee\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"'SSL Death Alert' (CVE-2016-8610) Can Cause Denial of Service to OpenSSL Servers | McAfee Blog","description":"Recently we noticed a security patch has been published for the OpenSSL vulnerability called SSL Death Alert. As with other serious security","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"og_locale":"en_US","og_type":"article","og_title":"'SSL Death Alert' (CVE-2016-8610) Can Cause Denial of Service to OpenSSL Servers | McAfee Blog","og_description":"Recently we noticed a security patch has been published for the OpenSSL vulnerability called SSL Death Alert. As with other serious security","og_url":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ssl-death-alert-cve-2016-8610-can-cause-denial-of-service-to-openssl-servers\/","og_site_name":"McAfee Blog","article_publisher":"https:\/\/www.facebook.com\/McAfee\/","article_author":"https:\/\/www.facebook.com\/McAfee\/","article_published_time":"2016-12-14T01:13:40+00:00","article_modified_time":"2025-06-06T08:03:21+00:00","og_image":[{"width":794,"height":435,"url":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-1.png","type":"image\/png"}],"author":"McAfee","twitter_card":"summary_large_image","twitter_creator":"@McAfee","twitter_site":"@McAfee","twitter_misc":{"Written by":"McAfee","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ssl-death-alert-cve-2016-8610-can-cause-denial-of-service-to-openssl-servers\/#article","isPartOf":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ssl-death-alert-cve-2016-8610-can-cause-denial-of-service-to-openssl-servers\/"},"author":{"name":"McAfee","@id":"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/47851fdb92fad9456152405839c92efa"},"headline":"&#8216;SSL Death Alert&#8217; (CVE-2016-8610) Can Cause Denial of Service to OpenSSL Servers","datePublished":"2016-12-14T01:13:40+00:00","dateModified":"2025-06-06T08:03:21+00:00","mainEntityOfPage":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ssl-death-alert-cve-2016-8610-can-cause-denial-of-service-to-openssl-servers\/"},"wordCount":587,"publisher":{"@id":"https:\/\/www.mcafee.com\/blogs\/#organization"},"image":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ssl-death-alert-cve-2016-8610-can-cause-denial-of-service-to-openssl-servers\/#primaryimage"},"thumbnailUrl":"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-1.png","keywords":["virtual patching","vulnerability"],"articleSection":["McAfee Labs"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ssl-death-alert-cve-2016-8610-can-cause-denial-of-service-to-openssl-servers\/","url":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ssl-death-alert-cve-2016-8610-can-cause-denial-of-service-to-openssl-servers\/","name":"'SSL Death Alert' (CVE-2016-8610) Can Cause Denial of Service to OpenSSL Servers | McAfee Blog","isPartOf":{"@id":"https:\/\/www.mcafee.com\/blogs\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ssl-death-alert-cve-2016-8610-can-cause-denial-of-service-to-openssl-servers\/#primaryimage"},"image":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ssl-death-alert-cve-2016-8610-can-cause-denial-of-service-to-openssl-servers\/#primaryimage"},"thumbnailUrl":"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-1.png","datePublished":"2016-12-14T01:13:40+00:00","dateModified":"2025-06-06T08:03:21+00:00","description":"Recently we noticed a security patch has been published for the OpenSSL vulnerability called SSL Death Alert. As with other serious security","breadcrumb":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ssl-death-alert-cve-2016-8610-can-cause-denial-of-service-to-openssl-servers\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ssl-death-alert-cve-2016-8610-can-cause-denial-of-service-to-openssl-servers\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ssl-death-alert-cve-2016-8610-can-cause-denial-of-service-to-openssl-servers\/#primaryimage","url":"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-1.png","contentUrl":"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2016-12-13-OpenSSL-Death-Alert-1.png"},{"@type":"BreadcrumbList","@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ssl-death-alert-cve-2016-8610-can-cause-denial-of-service-to-openssl-servers\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https:\/\/www.mcafee.com\/blogs\/"},{"@type":"ListItem","position":2,"name":"Other Blogs","item":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/"},{"@type":"ListItem","position":3,"name":"McAfee Labs","item":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/"},{"@type":"ListItem","position":4,"name":"&#8216;SSL Death Alert&#8217; (CVE-2016-8610) Can Cause Denial of Service to OpenSSL Servers"}]},{"@type":"WebSite","@id":"https:\/\/www.mcafee.com\/blogs\/#website","url":"https:\/\/www.mcafee.com\/blogs\/","name":"McAfee Blog","description":"Internet Security News","publisher":{"@id":"https:\/\/www.mcafee.com\/blogs\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.mcafee.com\/blogs\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.mcafee.com\/blogs\/#organization","name":"McAfee","url":"https:\/\/www.mcafee.com\/blogs\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.mcafee.com\/blogs\/#\/schema\/logo\/image\/","url":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/02\/mcafee-logo.png","contentUrl":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/02\/mcafee-logo.png","width":1286,"height":336,"caption":"McAfee"},"image":{"@id":"https:\/\/www.mcafee.com\/blogs\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/McAfee\/","https:\/\/x.com\/McAfee","https:\/\/www.linkedin.com\/company\/mcafee\/","https:\/\/www.youtube.com\/McAfee"]},{"@type":"Person","@id":"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/47851fdb92fad9456152405839c92efa","name":"McAfee","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/image\/1ffadfeeda1f4f9e7891a81f27a9ecf4","url":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2020\/08\/Original-Logo-96x96.png","contentUrl":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2020\/08\/Original-Logo-96x96.png","caption":"McAfee"},"description":"We're here to make life online safe and enjoyable for everyone.","sameAs":["https:\/\/www.facebook.com\/McAfee\/","https:\/\/www.linkedin.com\/company\/mcafee\/","https:\/\/x.com\/McAfee"],"url":"https:\/\/www.mcafee.com\/blogs\/author\/mcafee\/"}]}},"_links":{"self":[{"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/posts\/66242","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/users\/674"}],"replies":[{"embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/comments?post=66242"}],"version-history":[{"count":2,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/posts\/66242\/revisions"}],"predecessor-version":[{"id":215152,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/posts\/66242\/revisions\/215152"}],"wp:attachment":[{"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/media?parent=66242"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/categories?post=66242"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/tags?post=66242"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/coauthors?post=66242"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}