CVE-2012-2110

UnknownEPSS 48.30%

Last modified

CVE-2012-2110 is a vulnerability of currently unknown severity. The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in OpenSSL before 0.9.8v, 1.0.0 before 1.0.0i, and 1.0.1 before 1.0.1a does not properly interpret integer data, which allows remote attackers to conduct buffer overflow attacks, and cause a denial of service (memory corruption) or possibly have unspecified other impact, via crafted DER data, as demonstrated by an X.509 certificate or an RSA public key.. EPSS estimates a 48.30% chance of exploitation in the next 30 days.

Description

The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in OpenSSL before 0.9.8v, 1.0.0 before 1.0.0i, and 1.0.1 before 1.0.1a does not properly interpret integer data, which allows remote attackers to conduct buffer overflow attacks, and cause a denial of service (memory corruption) or possibly have unspecified other impact, via crafted DER data, as demonstrated by an X.509 certificate or an RSA public key.

Metrics

EPSS Probability
48.30%

98.7th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
OpensslOpenssl1.0.0—
OpensslOpenssl1.0.0a—
OpensslOpenssl1.0.0b—
OpensslOpenssl1.0.0c—
OpensslOpenssl1.0.0d—
OpensslOpenssl1.0.0e—
OpensslOpenssl1.0.0g—
OpensslOpenssl<= 0.9.8u—
OpensslOpenssl0.9.1c—
OpensslOpenssl0.9.2b—
OpensslOpenssl0.9.3—
OpensslOpenssl0.9.3a—
OpensslOpenssl0.9.4—
OpensslOpenssl0.9.5—
OpensslOpenssl0.9.5a—
OpensslOpenssl0.9.6—
OpensslOpenssl0.9.6a—
OpensslOpenssl0.9.6b—
OpensslOpenssl0.9.6c—
OpensslOpenssl0.9.6d—
OpensslOpenssl0.9.6e—
OpensslOpenssl0.9.6f—
OpensslOpenssl0.9.6g—
OpensslOpenssl0.9.6h—
OpensslOpenssl0.9.6i—
OpensslOpenssl0.9.6j—
OpensslOpenssl0.9.6k—
OpensslOpenssl0.9.6l—
OpensslOpenssl0.9.6m—
OpensslOpenssl0.9.7—
OpensslOpenssl0.9.7a—
OpensslOpenssl0.9.7b—
OpensslOpenssl0.9.7c—
OpensslOpenssl0.9.7d—
OpensslOpenssl0.9.7e—
OpensslOpenssl0.9.7f—
OpensslOpenssl0.9.7g—
OpensslOpenssl0.9.7h—
OpensslOpenssl0.9.7i—
OpensslOpenssl0.9.7j—
OpensslOpenssl0.9.7k—
OpensslOpenssl0.9.7l—
OpensslOpenssl0.9.7m—
OpensslOpenssl0.9.8—
OpensslOpenssl0.9.8a—
OpensslOpenssl0.9.8b—
OpensslOpenssl0.9.8c—
OpensslOpenssl0.9.8d—
OpensslOpenssl0.9.8e—
OpensslOpenssl0.9.8f—

Showing 50 of 68 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2012-2110?
The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in OpenSSL before 0.9.8v, 1.0.0 before 1.0.0i, and 1.0.1 before 1.0.1a does not properly interpret integer data, which allows remote attackers to conduct buffer overflow attacks, and cause a denial of service (memory corruption) or possibly have unspecified other impact, via crafted DER data, as demonstrated by an X.509 certificate or an RSA public key.
How severe is CVE-2012-2110?
Severity scoring for CVE-2012-2110 is pending analysis. The EPSS model estimates a 48.30% probability of exploitation in the next 30 days.
How do I fix CVE-2012-2110?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2012

Are you affected by CVE-2012-2110?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST