CVE-2012-2110

Description

The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in OpenSSL before 0.9.8v, 1.0.0 before 1.0.0i, and 1.0.1 before 1.0.1a does not properly interpret integer data, which allows remote attackers to conduct buffer overflow attacks, and cause a denial of service (memory corruption) or possibly have unspecified other impact, via crafted DER data, as demonstrated by an X.509 certificate or an RSA public key.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
7.426

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2012-2110 are fixed in OpenSSL (x64) 0.9.8vWindows
Vulnerabilities CVE-2012-2110 are fixed in OpenSSL (x64) 1.0.0iWindows
Vulnerabilities CVE-2012-2110 are fixed in OpenSSL (x64) 1.0.1aWindows
Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2012-2110)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234