LWN.net Logo

openssl: arbitrary code execution

Package(s):openssl CVE #(s):CVE-2010-0742
Created:June 15, 2010 Updated:June 22, 2010
Description: From the Pardus advisory:

The Cryptographic Message Syntax (CMS) implementation in crypto/cms/cms_asn1.c in OpenSSL before 0.9.8o and 1.x before 1.0.0a does not properly handle structures that contain OriginatorInfo, which allows context-dependent attackers to modify invalid memory locations or conduct double-free attacks, and possibly execute arbitrary code, via unspecified vectors.

Alerts:
Gentoo 201110-01 2011-10-09
Fedora FEDORA-2010-9639 2010-06-07
Fedora FEDORA-2010-9421 2010-06-02
Pardus 2010-77 2010-06-15
Fedora FEDORA-2010-9574 2010-06-07

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds