Описание
The mime_param_cmp function in crypto/asn1/asn_mime.c in OpenSSL before 0.9.8u and 1.x before 1.0.0h allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted S/MIME message, a different vulnerability than CVE-2006-7250.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 4 | openssl | Will not fix | ||
Red Hat Enterprise Linux 4 | openssl096b | Will not fix | ||
Red Hat Enterprise Linux 5 | openssl097a | Will not fix | ||
Red Hat Enterprise Linux 6 | openssl098e | Will not fix | ||
Red Hat JBoss Enterprise Web Server 1 | openssl | Affected | ||
Red Hat Enterprise Linux 5 | openssl | Fixed | RHSA-2012:0426 | 27.03.2012 |
Red Hat Enterprise Linux 6 | openssl | Fixed | RHSA-2012:0426 | 27.03.2012 |
Red Hat JBoss Enterprise Application Platform 5.1 | Fixed | RHSA-2012:1307 | 24.09.2012 | |
Red Hat JBoss Enterprise Application Platform 6.0 | Fixed | RHSA-2012:1308 | 24.09.2012 | |
Red Hat JBoss Web Server 1.0 | Fixed | RHSA-2012:1306 | 24.09.2012 |
Показывать по
Дополнительная информация
Статус:
EPSS
5 Medium
CVSS2
Связанные уязвимости
The mime_param_cmp function in crypto/asn1/asn_mime.c in OpenSSL before 0.9.8u and 1.x before 1.0.0h allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted S/MIME message, a different vulnerability than CVE-2006-7250.
The mime_param_cmp function in crypto/asn1/asn_mime.c in OpenSSL before 0.9.8u and 1.x before 1.0.0h allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted S/MIME message, a different vulnerability than CVE-2006-7250.
The mime_param_cmp function in crypto/asn1/asn_mime.c in OpenSSL befor ...
The mime_param_cmp function in crypto/asn1/asn_mime.c in OpenSSL before 0.9.8u and 1.x before 1.0.0h allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted S/MIME message, a different vulnerability than CVE-2006-7250.
ELSA-2012-0426: openssl security and bug fix update (MODERATE)
EPSS
5 Medium
CVSS2