Back to search
CVE-2012-2131
Published: Apr 24, 2012
Modified: Aug 6, 2024
PUBLISHED
Description
Multiple integer signedness errors in crypto/buffer/buffer.c in OpenSSL 0.9.8v allow remote attackers to conduct buffer overflow attacks, and cause a denial of service (memory corruption) or possibly have unspecified other impact, via crafted DER data, as demonstrated by an X.509 certificate or an RSA public key. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-2110.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
SUSE-SU-2012:0623
vendor-advisory
x_refsource_SUSE
SUSE-SU-2012:1149
vendor-advisory
x_refsource_SUSE
http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004564
x_refsource_CONFIRM
MDVSA-2012:064
vendor-advisory
x_refsource_MANDRIVA
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10673
x_refsource_CONFIRM
USN-1428-1
vendor-advisory
x_refsource_UBUNTU
http://cvs.openssl.org/chngview?cn=22479
x_refsource_CONFIRM
http://www.openssl.org/news/secadv_20120424.txt
x_refsource_CONFIRM
DSA-2454
vendor-advisory
x_refsource_DEBIAN
http://support.apple.com/kb/HT5784
x_refsource_CONFIRM
APPLE-SA-2013-06-04-1
vendor-advisory
x_refsource_APPLE
48895
third-party-advisory
x_refsource_SECUNIA
openssl-asn1-code-execution(75099)
vdb-entry
x_refsource_XF
48956
third-party-advisory
x_refsource_SECUNIA
[oss-security] 20120424 Re: OpenSSL ASN1 BIO vulnerability (CVE-2012-2110)
mailing-list
x_refsource_MLIST
SUSE-SU-2012:0637
vendor-advisory
x_refsource_SUSE
HPSBOV02793
vendor-advisory
x_refsource_HP
57353
third-party-advisory
x_refsource_SECUNIA
HPSBUX02782
vendor-advisory
x_refsource_HP
SSRT100891
vendor-advisory
x_refsource_HP
1026957
vdb-entry
x_refsource_SECTRACK
53212
vdb-entry
x_refsource_BID
SSRT100844
vendor-advisory
x_refsource_HP
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now