Описание
The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in OpenSSL before 0.9.8v, 1.0.0 before 1.0.0i, and 1.0.1 before 1.0.1a does not properly interpret integer data, which allows remote attackers to conduct buffer overflow attacks, and cause a denial of service (memory corruption) or possibly have unspecified other impact, via crafted DER data, as demonstrated by an X.509 certificate or an RSA public key.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 3 | openssl096b | Will not fix | ||
Red Hat Enterprise Linux 4 | openssl096b | Will not fix | ||
Red Hat Enterprise Linux Extended Update Support 5.3 | openssl | Affected | ||
Red Hat JBoss Enterprise Web Server 1 | openssl | Affected | ||
Red Hat Enterprise Linux 3 Extended Lifecycle Support | openssl | Fixed | RHSA-2012:0522 | 25.04.2012 |
Red Hat Enterprise Linux 4 Extended Lifecycle Support | openssl | Fixed | RHSA-2012:0522 | 25.04.2012 |
Red Hat Enterprise Linux 5 | openssl | Fixed | RHSA-2012:0518 | 24.04.2012 |
Red Hat Enterprise Linux 5 | openssl097a | Fixed | RHSA-2012:0518 | 24.04.2012 |
Red Hat Enterprise Linux 5.3 Long Life | openssl | Fixed | RHSA-2012:0522 | 25.04.2012 |
Red Hat Enterprise Linux 5.6 EUS - Server Only | openssl | Fixed | RHSA-2012:0522 | 25.04.2012 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS2
Связанные уязвимости
The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in OpenSSL before 0.9.8v, 1.0.0 before 1.0.0i, and 1.0.1 before 1.0.1a does not properly interpret integer data, which allows remote attackers to conduct buffer overflow attacks, and cause a denial of service (memory corruption) or possibly have unspecified other impact, via crafted DER data, as demonstrated by an X.509 certificate or an RSA public key.
The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in OpenSSL before 0.9.8v, 1.0.0 before 1.0.0i, and 1.0.1 before 1.0.1a does not properly interpret integer data, which allows remote attackers to conduct buffer overflow attacks, and cause a denial of service (memory corruption) or possibly have unspecified other impact, via crafted DER data, as demonstrated by an X.509 certificate or an RSA public key.
The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in OpenSSL be ...
The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in OpenSSL before 0.9.8v, 1.0.0 before 1.0.0i, and 1.0.1 before 1.0.1a does not properly interpret integer data, which allows remote attackers to conduct buffer overflow attacks, and cause a denial of service (memory corruption) or possibly have unspecified other impact, via crafted DER data, as demonstrated by an X.509 certificate or an RSA public key.
EPSS
7.5 High
CVSS2