HIGH
openssl: invalid ASN1 module definition for CMS
Published Jun 3, 2010
7.5
HIGHCVSS 2.0
EPSS 7.83%
Description
The Cryptographic Message Syntax (CMS) implementation in crypto/cms/cms_asn1.c in OpenSSL before 0.9.8o and 1.x before 1.0.0a does not properly handle structures that contain OriginatorInfo, which allows context-dependent attackers to modify invalid memory locations or conduct double-free attacks, and possibly execute arbitrary code, via unspecified vectors.
Affected products
No data.
Configuration 1
OR
- ≤ 0.9.8n
- 0.9.1c
- 0.9.2b
- 0.9.3
- 0.9.3a
- 0.9.4
- 0.9.5
- 0.9.5
- 0.9.5
- 0.9.5a
- 0.9.5a
- 0.9.5a
- 0.9.6
- 0.9.6
- 0.9.6
- 0.9.6
- 0.9.6a
- 0.9.6a
- 0.9.6a
- 0.9.6a
- 0.9.6b
- 0.9.6c
- 0.9.6d
- 0.9.6e
- 0.9.6f
- 0.9.6g
- 0.9.6h
- 0.9.6i
- 0.9.6j
- 0.9.6k
- 0.9.6l
- 0.9.6m
- 0.9.7
- 0.9.7
- 0.9.7
- 0.9.7
- 0.9.7
- 0.9.7
- 0.9.7
- 0.9.7a
- 0.9.7b
- 0.9.7c
- 0.9.7d
- 0.9.7e
- 0.9.7f
- 0.9.7g
- 0.9.7h
- 0.9.7i
- 0.9.7j
- 0.9.7k
- 0.9.7l
- 0.9.7m
- 0.9.8
- 0.9.8a
- 0.9.8b
- 0.9.8c
- 0.9.8d
- 0.9.8e
- 0.9.8f
- 0.9.8g
- 0.9.8h
- 0.9.8i
- 0.9.8j
- 0.9.8k
- 0.9.8l
- 0.9.8m
No data.
Red Hat Enterprise Linux 6
openssl
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | openssl | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Not vulnerable. These issues did not affect the versions of OpenSSL as shipped with Red Hat Enterprise Linux 3, 4, or 5.
Weaknesses (1)
References (23)
- http://cvs.openssl.org/chngview?cn=19693 x_refsource_CONFIRM
- http://cvs.openssl.org/filediff?f=openssl/crypto/cms/cms_asn1.c&v1=1.8&v2=1.8.6.1 x_refsource_CONFIRM
- http://marc.info/?l=bugtraq&m=129138643405740&w=2 vendor-advisoryx_refsource_HP
- http://rt.openssl.org/Ticket/Display.html?id=2211&user=guest&pass=guest x_refsource_CONFIRM
- http://secunia.com/advisories/40000 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/40024 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/42457 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/42724 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/42733 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/57353 third-party-advisoryx_refsource_SECUNIA
- http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004564 x_refsource_CONFIRM
- http://www.openssl.org/news/secadv_20100601.txt x_refsource_CONFIRM
- http://www.securityfocus.com/bid/40502 vdb-entryx_refsource_BID
- http://www.vupen.com/english/advisories/2010/1313 vdb-entryx_refsource_VUPENPatchVendor Advisory
- http://www.vupen.com/english/advisories/2010/3105 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2010-0742 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=598738 x_refsource_CONFIRMIssue Tracking
- https://kb.bluecoat.com/index?page=content&id=SA50 x_refsource_CONFIRM
- https://lists.balabit.com/pipermail/syslog-ng-announce/2011-January/000101.html mailing-listx_refsource_MLIST
- https://lists.balabit.com/pipermail/syslog-ng-announce/2011-January/000102.html mailing-listx_refsource_MLIST
- https://nvd.nist.gov/vuln/detail/CVE-2010-0742
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12395 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2010-0742
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jun 3, 2010
Updated Aug 7, 2024
Reserved Feb 26, 2010
Link CVE-2010-0742
CISA Vulnrichment
Updated n/a