LWN.net Logo

openssl: exploitable vulnerability

Package(s):openssl CVE #(s):CVE-2012-2110
Created:April 19, 2012 Updated:May 10, 2012
Description:

A rather unhelpful description from the OpenSSL advisory:

A potentially exploitable vulnerability has been discovered in the OpenSSL function asn1_d2i_read_bio.

Any application which uses BIO or FILE based functions to read untrusted DER format data is vulnerable. Affected functions are of the form d2i_*_bio or d2i_*_fp, for example d2i_X509_bio or d2i_PKCS12_fp.

Alerts:
Mandriva MDVSA-2012:060 2012-04-19
Debian DSA-2454-1 2012-04-19
Ubuntu USN-1424-1 2012-04-19
Red Hat RHSA-2012:0518-01 2012-04-24
Red Hat RHSA-2012:0522-01 2012-04-25
CentOS CESA-2012:0518 2012-04-25
CentOS CESA-2012:0518 2012-04-25
Scientific Linux SL-open-20120425 2012-04-25
Oracle ELSA-2012-0518 2012-04-25
Oracle ELSA-2012-0518 2012-04-25
Fedora FEDORA-2012-6403 2012-04-27
Oracle ELSA-2012-2011 2012-05-08
Fedora FEDORA-2012-6395 2012-05-10
SUSE SUSE-SU-2012:0623-1 2012-05-16
SUSE SUSE-SU-2012:0637-1 2012-05-23
SUSE SUSE-SU-2012:0674-1 2012-05-30
SUSE SUSE-SU-2012:1149-1 2012-09-12
SUSE SUSE-SU-2012:1149-2 2012-09-18
openSUSE openSUSE-SU-2013:0336-1 2013-02-25
Oracle ELSA-2013-0587 2013-03-05

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds