CVE-2012-2110
Last modified
CVE-2012-2110 is a vulnerability of currently unknown severity. The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in OpenSSL before 0.9.8v, 1.0.0 before 1.0.0i, and 1.0.1 before 1.0.1a does not properly interpret integer data, which allows remote attackers to conduct buffer overflow attacks, and cause a denial of service (memory corruption) or possibly have unspecified other impact, via crafted DER data, as demonstrated by an X.509 certificate or an RSA public key.. EPSS estimates a 48.30% chance of exploitation in the next 30 days.
Description
The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in OpenSSL before 0.9.8v, 1.0.0 before 1.0.0i, and 1.0.1 before 1.0.1a does not properly interpret integer data, which allows remote attackers to conduct buffer overflow attacks, and cause a denial of service (memory corruption) or possibly have unspecified other impact, via crafted DER data, as demonstrated by an X.509 certificate or an RSA public key.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Openssl | Openssl | 1.0.0 | — |
| Openssl | Openssl | 1.0.0a | — |
| Openssl | Openssl | 1.0.0b | — |
| Openssl | Openssl | 1.0.0c | — |
| Openssl | Openssl | 1.0.0d | — |
| Openssl | Openssl | 1.0.0e | — |
| Openssl | Openssl | 1.0.0g | — |
| Openssl | Openssl | <= 0.9.8u | — |
| Openssl | Openssl | 0.9.1c | — |
| Openssl | Openssl | 0.9.2b | — |
| Openssl | Openssl | 0.9.3 | — |
| Openssl | Openssl | 0.9.3a | — |
| Openssl | Openssl | 0.9.4 | — |
| Openssl | Openssl | 0.9.5 | — |
| Openssl | Openssl | 0.9.5a | — |
| Openssl | Openssl | 0.9.6 | — |
| Openssl | Openssl | 0.9.6a | — |
| Openssl | Openssl | 0.9.6b | — |
| Openssl | Openssl | 0.9.6c | — |
| Openssl | Openssl | 0.9.6d | — |
| Openssl | Openssl | 0.9.6e | — |
| Openssl | Openssl | 0.9.6f | — |
| Openssl | Openssl | 0.9.6g | — |
| Openssl | Openssl | 0.9.6h | — |
| Openssl | Openssl | 0.9.6i | — |
| Openssl | Openssl | 0.9.6j | — |
| Openssl | Openssl | 0.9.6k | — |
| Openssl | Openssl | 0.9.6l | — |
| Openssl | Openssl | 0.9.6m | — |
| Openssl | Openssl | 0.9.7 | — |
| Openssl | Openssl | 0.9.7a | — |
| Openssl | Openssl | 0.9.7b | — |
| Openssl | Openssl | 0.9.7c | — |
| Openssl | Openssl | 0.9.7d | — |
| Openssl | Openssl | 0.9.7e | — |
| Openssl | Openssl | 0.9.7f | — |
| Openssl | Openssl | 0.9.7g | — |
| Openssl | Openssl | 0.9.7h | — |
| Openssl | Openssl | 0.9.7i | — |
| Openssl | Openssl | 0.9.7j | — |
| Openssl | Openssl | 0.9.7k | — |
| Openssl | Openssl | 0.9.7l | — |
| Openssl | Openssl | 0.9.7m | — |
| Openssl | Openssl | 0.9.8 | — |
| Openssl | Openssl | 0.9.8a | — |
| Openssl | Openssl | 0.9.8b | — |
| Openssl | Openssl | 0.9.8c | — |
| Openssl | Openssl | 0.9.8d | — |
| Openssl | Openssl | 0.9.8e | — |
| Openssl | Openssl | 0.9.8f | — |
Showing 50 of 68 affected configurations. See NVD for the full list.
References
- http://www.openssl.org/news/secadv_20120419.txtVendor Advisory
- http://www.openssl.org/news/secadv_20120419.txtVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-2110?
How severe is CVE-2012-2110?
How do I fix CVE-2012-2110?
Are you affected by CVE-2012-2110?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
