PT-2012-1111 · Openssl+1 · Openssl+1
Published
2012-01-04
·
Updated
2024-06-15
·
CVE-2012-0027
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
OpenSSL versions prior to 1.0.0g
Description
The issue allows remote attackers to cause problems with the service, potentially leading to a denial of service (daemon crash) via crafted data from a TLS client. Multiple issues in the OpenSSL package can lead to breaches of confidentiality, integrity, and availability of protected information. These issues can be exploited remotely.
Recommendations
For versions prior to 1.0.0g, update to version 1.0.0g or later to resolve the issue.
At the moment, there is no information about additional mitigation measures for this specific issue.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openssl
Suse