|
|
| |
|
| |
openssl: exploitable vulnerability
| Package(s): | openssl |
CVE #(s): | CVE-2012-2110
|
| Created: | April 19, 2012 |
Updated: | May 10, 2012 |
| Description: |
A rather unhelpful description from the OpenSSL advisory:
A potentially exploitable vulnerability has been discovered in the OpenSSL
function asn1_d2i_read_bio.
Any application which uses BIO or FILE based functions to read untrusted DER
format data is vulnerable. Affected functions are of the form d2i_*_bio or
d2i_*_fp, for example d2i_X509_bio or d2i_PKCS12_fp. |
| Alerts: |
|
( Log in to post comments)
|
|
|