#VU33326 Input validation error in OpenSSL - CVE-2012-0050
Published: January 19, 2012 / Updated: August 3, 2020
Vulnerability identifier: #VU33326
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2012-0050
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
OpenSSL
OpenSSL
Software vendor:
OpenSSL Software Foundation
OpenSSL Software Foundation
Description
The vulnerability allows remote attackers to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can cause a denial of service (crash) via unspecified vectors related to an out-of-bounds read.
Remediation
Update to version 0.9.8t.
External links
- http://aix.software.ibm.com/aix/efixes/security/openssl_advisory3.asc
- http://h20565.www2.hp.com/portal/site/hpsc/public/kb/docDisplay/?docId=emr_na-c03169289
- http://lists.apple.com/archives/security-announce/2013/Jun/msg00000.html
- http://marc.info/?l=bugtraq&m=133951357207000&w=2
- http://marc.info/?l=bugtraq&m=134039053214295&w=2
- http://osvdb.org/78320
- http://secunia.com/advisories/47631
- http://secunia.com/advisories/47677
- http://secunia.com/advisories/47755
- http://secunia.com/advisories/48528
- http://secunia.com/advisories/57353
- http://support.apple.com/kb/HT5784
- http://www.debian.org/security/2012/dsa-2392
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:011
- http://www.openssl.org/news/secadv_20120118.txt
- http://www.securityfocus.com/bid/51563
- http://www.securitytracker.com/id?1026548
- http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004564