CVE-2012-2110
CVE-2012-2110
The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in OpenSSL before 0.9.8v, 1.0.0 before 1.0.0i, and 1.0.1 before 1.0.1a does not properly interpret integer data, which allows remote attackers to conduct buffer overflow attacks, and cause a denial of service (memory corruption) or possibly have unspecified other impact, via crafted DER data, as demonstrated by an X.509 certificate or an RSA public key.
Produtos afetados
n/a · n/aPoCs públicas encontradas — 2
cve_referencewww.exploit-db.com/exploits/18756não verificadoexploitdbwww.exploit-db.com/exploits/18756não verificado⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.
Quer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://archives.neohapsis.com/archives/fulldisclosure/2012-04/0209.htmlhttp://cvs.openssl.org/chngview?cn=22431http://cvs.openssl.org/chngview?cn=22434http://cvs.openssl.org/chngview?cn=22439http://lists.apple.com/archives/security-announce/2013/Jun/msg00000.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-April/079149.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-April/079299.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-May/080176.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-November/092905.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-05/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-05/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00007.html