PT-2012-1078 · Openssl+4 · Openssl+4

Published

2012-01-04

·

Updated

2024-06-15

·

CVE-2011-4577

CVSS v2.0

7.6

High

VectorAV:N/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions OpenSSL versions prior to 1.0.0f OpenSSL versions prior to 0.9.8s OpenSSL version 1.0.0 openssl-devel version 1.0.0 openssl-debuginfo version 1.0.0 openssl-static version 1.0.0
Description The issue affects the confidentiality, integrity, and availability of protected information. Exploitation of the vulnerabilities can be done remotely. The vulnerabilities are related to the handling of X.509 certificate containing certificate-extension data associated with IP address blocks or Autonomous System (AS) identifiers when RFC 3779 support is enabled.
Recommendations For OpenSSL versions prior to 1.0.0f, update to version 1.0.0f or later. For OpenSSL versions prior to 0.9.8s, update to version 0.9.8s or later. For openssl-devel version 1.0.0, update to a version that is not affected by the vulnerability. For openssl-debuginfo version 1.0.0, update to a version that is not affected by the vulnerability. For openssl-static version 1.0.0, update to a version that is not affected by the vulnerability. As a temporary workaround, consider disabling RFC 3779 support until a patch is available.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-06476
BDU:2015-06477
BDU:2015-06479
BDU:2015-06480
BDU:2015-08802
BDU:2015-08803
BDU:2015-08804
BDU:2015-08805
BDU:2015-09442
CESA-2012_0059
CVE-2011-4577
HPSBUX02734
OPENSUSE-SU-2024:10271-1
OPENSUSE-SU-2024:10529-1
OPENSUSE-SU-2024:11127-1
RHSA-2012:0059
RHSA-2012:0109
RHSA-2012_0059
SUSE-FU-2022:0445-1
SUSE-SU-2015:1184-1
SUSE-SU-403

Affected Products

Centos
Hp-Ux
Openssl
Red Hat
Suse