LWN.net Logo

openssl: denial of service

Package(s):openssl CVE #(s):CVE-2012-2686
Created:February 21, 2013 Updated:February 27, 2013
Description: From the Ubuntu advisory:

Adam Langley and Wolfgang Ettlingers discovered that OpenSSL incorrectly handled certain crafted CBC data when used with AES-NI. A remote attacker could use this issue to cause OpenSSL to crash, resulting in a denial of service.

Alerts:
Ubuntu USN-1732-1 2013-02-21
openSUSE openSUSE-SU-2013:0337-1 2013-02-25
openSUSE openSUSE-SU-2013:0336-1 2013-02-25
openSUSE openSUSE-SU-2013:0339-1 2013-02-25
Ubuntu USN-1732-2 2013-02-28
Ubuntu USN-1732-3 2013-03-25

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds