CVE-2012-2333
8Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackepss 28%
probabilidade de exploração
28%top 2% das CVEs
exploração observada
nãonenhuma fonte reporta
Integer underflow in OpenSSL before 0.9.8x, 1.0.0 before 1.0.0j, and 1.0.1 before 1.0.1c, when TLS 1.1, TLS 1.2, or DTLS is used with CBC encryption, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted TLS packet that is not properly handled during a certain explicit IV calculation.
Produtos afetados
n/a · n/aReferências
http://cvs.openssl.org/chngview?cn=22538http://cvs.openssl.org/chngview?cn=22547http://lists.apple.com/archives/security-announce/2013/Jun/msg00000.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-May/081460.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-November/092905.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-05/msg00019.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-05/msg00020.htmlhttp://marc.info/?l=bugtraq&m=134919053717161&w=2http://marc.info/?l=bugtraq&m=136432043316835&w=2http://rhn.redhat.com/errata/RHSA-2012-0699.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1306.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1307.html