SB2012051409 - Out-of-bounds read in openssl (Alpine package)
Published: May 14, 2012
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2012-2333)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in Integer underflow in OpenSSL before 0.9.8x, 1.0.0 before 1.0.0j, and 1.0.1 before 1.0.1c, when TLS 1.1, TLS 1.2, or DTLS is used with CBC encryption,. A remote attacker can perform a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted TLS packet that is not properly handled during a certain explicit IV calculation.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=48d01c7c6a2f0100405a9577d9cdd631d3fa9800
- https://git.alpinelinux.org/aports/commit/?id=049f48d3fd138f93aa604f3a89e18030585e9997
- https://git.alpinelinux.org/aports/commit/?id=8d888cd61622ac57243993b73a882c9072b96b94
- https://git.alpinelinux.org/aports/commit/?id=1831053bb87f432f0d45ccd9f7a368fc885a1d64