CVE-2012-2131

NameCVE-2012-2131
DescriptionMultiple integer signedness errors in crypto/buffer/buffer.c in OpenSSL 0.9.8v allow remote attackers to conduct buffer overflow attacks, and cause a denial of service (memory corruption) or possibly have unspecified other impact, via crafted DER data, as demonstrated by an X.509 certificate or an RSA public key. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-2110.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-2454-2
NVD severityhigh (attack range: remote)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
openssl (PTS)wheezy1.0.1e-2+deb7u20fixed
wheezy (security)1.0.1t-1+deb7u1fixed
jessie1.0.1t-1+deb8u3fixed
jessie (security)1.0.1t-1+deb8u5fixed
stretch1.0.2h-1fixed
sid1.0.2i-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
opensslsource(unstable)(not affected)
opensslsourcesqueeze0.9.8o-4squeeze12highDSA-2454-2

Notes

- openssl <not-affected> (only affected patch against 0.9.8)
http://marc.info/?l=openssl-dev&m=133525318514423&w=2

Search for package or bug name: Reporting problems