CVE-2012-2131
Publication date 24 April 2012
Last updated 24 July 2024
Ubuntu priority
Multiple integer signedness errors in crypto/buffer/buffer.c in OpenSSL 0.9.8v allow remote attackers to conduct buffer overflow attacks, and cause a denial of service (memory corruption) or possibly have unspecified other impact, via crafted DER data, as demonstrated by an X.509 certificate or an RSA public key. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-2110.
Status
Package | Ubuntu Release | Status |
---|---|---|
openssl | ||
openssl098 | ||
Notes
mdeslaur
1.0.x not affected by CVE-2012-2131 all releases also have second patch to fix incorrect error code introduced in the fix for CVE-2012-2110
Patch details
Package | Patch details |
---|---|
openssl |
|
References
Related Ubuntu Security Notices (USN)
- USN-1428-1
- OpenSSL vulnerability
- 24 April 2012