CVE-2012-0884
Publication date 12 March 2012
Last updated 24 July 2024
Ubuntu priority
The implementation of Cryptographic Message Syntax (CMS) and PKCS #7 in OpenSSL before 0.9.8u and 1.x before 1.0.0h does not properly restrict certain oracle behavior, which makes it easier for context-dependent attackers to decrypt data via a Million Message Attack (MMA) adaptive chosen ciphertext attack.
Status
Package | Ubuntu Release | Status |
---|---|---|
openssl | 14.04 LTS trusty |
Not affected
|
openssl098 | 14.04 LTS trusty |
Fixed 0.9.8o-7ubuntu3.2.14.04.1
|
Notes
sbeattie
only affects CMS, PKCS #7, or S/MIME decryption, not SSL/TLS transactions
mdeslaur
from oss-security: "If a Linux distribution picks up the fix for CVE-2012-0884 then they will want to pick up change 22161 at the same time since the fix for the security vulnerability will generally cause symmetric decryption errors when it kicks in and things get very confusing for the end user without change 22161" A second issue was fixed too, see: http://www.openwall.com/lists/oss-security/2012/05/11/5
Patch details
Package | Patch details |
---|---|
openssl |
|
References
Related Ubuntu Security Notices (USN)
- USN-1451-1
- OpenSSL vulnerabilities
- 24 May 2012