Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <20120420091119.GA25342@openwall.com>
Date: Fri, 20 Apr 2012 13:11:19 +0400
From: Solar Designer <solar@...nwall.com>
To: oss-security@...ts.openwall.com
Cc: Tavis Ormandy <taviso@...xchg8b.com>
Subject: OpenSSL ASN1 BIO vulnerability (CVE-2012-2110)

Hi,

This should have been posted in here yesterday (and by someone more
familiar with the topic), but better a bit late than never.

Tavis Ormandy of Google Security Team found a vulnerability in OpenSSL:

incorrect integer conversions in OpenSSL can result in memory corruption.
http://lists.openwall.net/full-disclosure/2012/04/19/4

Advisory from OpenSSL:
http://openssl.org/news/secadv_20120419.txt

Fortunately, the SSL/TLS code of OpenSSL is not affected - but some
other uses of OpenSSL are.

There are updates for 1.0.1, 1.0.0, and 0.9.8.

Alexander

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.