PT-2012-1111 · Openssl+1 · Openssl+1
Publicado
2012-01-04
·
Atualizado
2024-06-15
·
CVE-2012-0027
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
OpenSSL versions prior to 1.0.0g
Description
The issue allows remote attackers to cause problems with the service, potentially leading to a denial of service (daemon crash) via crafted data from a TLS client. Multiple issues in the OpenSSL package can lead to breaches of confidentiality, integrity, and availability of protected information. These issues can be exploited remotely.
Recommendations
For versions prior to 1.0.0g, update to version 1.0.0g or later to resolve the issue.
At the moment, there is no information about additional mitigation measures for this specific issue.
Correção
DoS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Openssl
Suse