Release date:
Updated on:
Affected Systems:
OpenSSL Project OpenSSL 1.x
OpenSSL Project OpenSSL 0.x
Unaffected system:
OpenSSL Project OpenSSL 1.0.0h 0
OpenSSL Project OpenSSL 0.9.8u 0
Description:
--------------------------------------------------------------------------------
Bugtraq id: 52764
Cve id: CVE-2012-1165
OpenSSL is an open-source SSL implementation that implements high-strength encryption for network communication. It is widely used in various network applications.
OpenSSL has a remote denial of service vulnerability in the implementation of malformed S/MIME messages. Attackers can exploit this vulnerability to crash affected applications.
<* Source: Tomas Hoger (thoger@redhat.com)
Link: http://www.openwall.com/lists/oss-security/2012/03/13/2
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
OpenSSL Project
---------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.openssl.org/