openssl: asn1_d2i_read_bio integer errors leading to buffer overflow
Published Apr 19, 2012
7.5
HIGHCVSS 2.0
EPSS 47.91%
Description
The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in OpenSSL before 0.9.8v, 1.0.0 before 1.0.0i, and 1.0.1 before 1.0.1a does not properly interpret integer data, which allows remote attackers to conduct buffer overflow attacks, and cause a denial of service (memory corruption) or possibly have unspecified other impact, via crafted DER data, as demonstrated by an X.509 certificate or an RSA public key.
Affected products
No data.
Configuration 1
- 1.0.0
- 1.0.0
- 1.0.0
- 1.0.0
- 1.0.0
- 1.0.0
- 1.0.0a
- 1.0.0b
- 1.0.0c
- 1.0.0d
- 1.0.0e
- 1.0.0g
Configuration 2
- ≤ 0.9.8u
- 0.9.1c
- 0.9.2b
- 0.9.3
- 0.9.3a
- 0.9.4
- 0.9.5
- 0.9.5
- 0.9.5
- 0.9.5a
- 0.9.5a
- 0.9.5a
- 0.9.6
- 0.9.6
- 0.9.6
- 0.9.6
- 0.9.6a
- 0.9.6a
- 0.9.6a
- 0.9.6a
- 0.9.6b
- 0.9.6c
- 0.9.6d
- 0.9.6e
- 0.9.6f
- 0.9.6g
- 0.9.6h
- 0.9.6i
- 0.9.6j
- 0.9.6k
- 0.9.6l
- 0.9.6m
- 0.9.7
- 0.9.7
- 0.9.7
- 0.9.7
- 0.9.7
- 0.9.7
- 0.9.7
- 0.9.7a
- 0.9.7b
- 0.9.7c
- 0.9.7d
- 0.9.7e
- 0.9.7f
- 0.9.7g
- 0.9.7h
- 0.9.7i
- 0.9.7j
- 0.9.7k
- 0.9.7l
- 0.9.7m
- 0.9.8
- 0.9.8a
- 0.9.8b
- 0.9.8c
- 0.9.8d
- 0.9.8e
- 0.9.8f
- 0.9.8g
- 0.9.8h
- 0.9.8i
- 0.9.8j
- 0.9.8k
- 0.9.8l
- 0.9.8m
- 0.9.8m
- 0.9.8n
- 0.9.8o
- 0.9.8p
- 0.9.8q
- 0.9.8r
- 0.9.8s
- 0.9.8t
- 0.9.6-15
- 0.9.6b-3
- 0.9.7a-2
No data.
Red Hat Enterprise Linux 3 Extended Lifecycle Support
openssl-0:0.9.7a-33.28
Fixed · RHSA-2012:0522
Red Hat Enterprise Linux 4 Extended Lifecycle Support
openssl-0:0.9.7a-43.20.el4
Fixed · RHSA-2012:0522
Red Hat Enterprise Linux 5
openssl-0:0.9.8e-22.el5_8.3
Fixed · RHSA-2012:0518
Red Hat Enterprise Linux 5
openssl097a-0:0.9.7a-11.el5_8.2
Fixed · RHSA-2012:0518
Red Hat Enterprise Linux 5.3 Long Life
openssl-0:0.9.8e-7.el5_3.2
Fixed · RHSA-2012:0522
Red Hat Enterprise Linux 5.6 EUS - Server Only
openssl-0:0.9.8e-12.el5_6.9
Fixed · RHSA-2012:0522
Red Hat Enterprise Linux 6
openssl-0:1.0.0-20.el6_2.4
Fixed · RHSA-2012:0518
Red Hat Enterprise Linux 6
openssl098e-0:0.9.8e-17.el6_2.2
Fixed · RHSA-2012:0518
Red Hat Enterprise Linux 6.0 EUS - Server Only
openssl-0:1.0.0-4.el6_0.3
Fixed · RHSA-2012:0522
Red Hat Enterprise Linux 6.1 EUS - Server Only
openssl-0:1.0.0-10.el6_1.6
Fixed · RHSA-2012:0522
Red Hat JBoss Enterprise Application Platform 5.1
n/a
Fixed · RHSA-2012:1307
Red Hat JBoss Enterprise Application Platform 6.0
n/a
Fixed · RHSA-2012:1308
Red Hat JBoss Web Server 1.0
n/a
Fixed · RHSA-2012:1306
Red Hat Enterprise Linux 4
openssl096b
Will not fix
Red Hat JBoss Enterprise Web Server 1
openssl
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 3 Extended Lifecycle Support | openssl-0:0.9.7a-33.28 | Fixed | RHSA-2012:0522 |
| Red Hat Enterprise Linux 4 Extended Lifecycle Support | openssl-0:0.9.7a-43.20.el4 | Fixed | RHSA-2012:0522 |
| Red Hat Enterprise Linux 5 | openssl-0:0.9.8e-22.el5_8.3 | Fixed | RHSA-2012:0518 |
| Red Hat Enterprise Linux 5 | openssl097a-0:0.9.7a-11.el5_8.2 | Fixed | RHSA-2012:0518 |
| Red Hat Enterprise Linux 5.3 Long Life | openssl-0:0.9.8e-7.el5_3.2 | Fixed | RHSA-2012:0522 |
| Red Hat Enterprise Linux 5.6 EUS - Server Only | openssl-0:0.9.8e-12.el5_6.9 | Fixed | RHSA-2012:0522 |
| Red Hat Enterprise Linux 6 | openssl-0:1.0.0-20.el6_2.4 | Fixed | RHSA-2012:0518 |
| Red Hat Enterprise Linux 6 | openssl098e-0:0.9.8e-17.el6_2.2 | Fixed | RHSA-2012:0518 |
| Red Hat Enterprise Linux 6.0 EUS - Server Only | openssl-0:1.0.0-4.el6_0.3 | Fixed | RHSA-2012:0522 |
| Red Hat Enterprise Linux 6.1 EUS - Server Only | openssl-0:1.0.0-10.el6_1.6 | Fixed | RHSA-2012:0522 |
| Red Hat JBoss Enterprise Application Platform 5.1 | n/a | Fixed | RHSA-2012:1307 |
| Red Hat JBoss Enterprise Application Platform 6.0 | n/a | Fixed | RHSA-2012:1308 |
| Red Hat JBoss Web Server 1.0 | n/a | Fixed | RHSA-2012:1306 |
| Red Hat Enterprise Linux 4 | openssl096b | Will not fix | n/a |
| Red Hat JBoss Enterprise Web Server 1 | openssl | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (44 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 47.91% (0.47913) | 98.82th | v5 (v2026.06.15) |
| Jun 15, 2026 | 48.30% (0.48298) | 98.71th | v5 (v2026.06.15) |
| Mar 11, 2026 | 8.74% (0.08744) | 92.37th | v4 (v2025.03.14) |
| Mar 4, 2026 | 7.43% (0.07426) | 91.59th | v4 (v2025.03.14) |
| Mar 1, 2026 | 11.03% (0.11033) | 93.33th | v4 (v2025.03.14) |
| Feb 4, 2026 | 7.43% (0.07426) | 91.53th | v4 (v2025.03.14) |
| Feb 1, 2026 | 11.03% (0.11033) | 93.28th | v4 (v2025.03.14) |
| Jan 4, 2026 | 7.52% (0.07525) | 91.51th | v4 (v2025.03.14) |
| Jan 1, 2026 | 10.57% (0.10572) | 93.08th | v4 (v2025.03.14) |
| Dec 19, 2025 | 7.52% (0.07525) | 91.48th | v4 (v2025.03.14) |
| Dec 4, 2025 | 5.11% (0.05113) | 89.43th | v4 (v2025.03.14) |
| Dec 1, 2025 | 7.28% (0.07282) | 91.34th | v4 (v2025.03.14) |
| Nov 4, 2025 | 6.28% (0.06281) | 90.50th | v4 (v2025.03.14) |
| Nov 1, 2025 | 7.75% (0.07749) | 91.57th | v4 (v2025.03.14) |
| Oct 4, 2025 | 6.28% (0.06281) | 90.55th | v4 (v2025.03.14) |
| Oct 1, 2025 | 7.75% (0.07749) | 91.63th | v4 (v2025.03.14) |
| Sep 4, 2025 | 5.89% (0.05888) | 90.26th | v4 (v2025.03.14) |
| Sep 1, 2025 | 7.27% (0.07273) | 91.33th | v4 (v2025.03.14) |
| Aug 4, 2025 | 5.89% (0.05888) | 90.24th | v4 (v2025.03.14) |
| Aug 1, 2025 | 7.27% (0.07273) | 91.31th | v4 (v2025.03.14) |
| Jul 4, 2025 | 6.20% (0.06197) | 90.41th | v4 (v2025.03.14) |
| Jul 1, 2025 | 8.10% (0.08102) | 91.77th | v4 (v2025.03.14) |
| Jun 4, 2025 | 6.28% (0.06281) | 90.42th | v4 (v2025.03.14) |
| Jun 1, 2025 | 7.75% (0.07749) | 91.51th | v4 (v2025.03.14) |
| May 4, 2025 | 6.28% (0.06281) | 90.39th | v4 (v2025.03.14) |
| May 1, 2025 | 7.75% (0.07749) | 91.49th | v4 (v2025.03.14) |
| Apr 12, 2025 | 6.28% (0.06281) | 90.05th | v4 (v2025.03.14) |
| Apr 11, 2025 | 7.75% (0.07749) | 91.17th | v4 (v2025.03.14) |
| Mar 30, 2025 | 6.28% (0.06281) | 89.98th | v4 (v2025.03.14) |
| Mar 29, 2025 | 16.07% (0.16072) | 91.36th | v4 (v2025.03.14) |
| Mar 27, 2025 | 6.28% (0.06281) | 89.56th | v4 (v2025.03.14) |
| Mar 26, 2025 | 7.75% (0.07749) | 91.06th | v4 (v2025.03.14) |
| Mar 22, 2025 | 6.28% (0.06281) | 90.09th | v4 (v2025.03.14) |
| Mar 21, 2025 | 7.75% (0.07749) | 91.23th | v4 (v2025.03.14) |
| Mar 18, 2025 | 6.28% (0.06281) | 90.26th | v4 (v2025.03.14) |
| Mar 17, 2025 | 7.75% (0.07749) | 91.33th | v4 (v2025.03.14) |
| Dec 12, 2024 | 11.83% (0.11827) | 95.55th | v3 (v2023.03.01) |
| Dec 8, 2024 | 11.83% (0.11827) | 95.54th | v3 (v2023.03.01) |
| May 8, 2024 | 9.99% (0.09994) | 94.84th | v3 (v2023.03.01) |
| Mar 10, 2023 | 11.01% (0.11013) | 94.19th | v3 (v2023.03.01) |
| Mar 7, 2023 | 12.70% (0.12700) | 94.53th | v3 (v2023.03.01) |
| Mar 6, 2023 | 7.56% (0.07559) | 92.87th | v2 (v2022.01.01) |
| Apr 1, 2022 | 7.56% (0.07559) | 92.17th | v2 (v2022.01.01) |
| Feb 4, 2022 | 7.56% (0.07559) | 81.11th | v2 (v2022.01.01) |
References (43)
- http://archives.neohapsis.com/archives/fulldisclosure/2012-04/0209.html mailing-listx_refsource_FULLDISCExploit
- http://cvs.openssl.org/chngview?cn=22431 x_refsource_CONFIRM
- http://cvs.openssl.org/chngview?cn=22434 x_refsource_CONFIRM
- http://cvs.openssl.org/chngview?cn=22439 x_refsource_CONFIRM
- http://lists.apple.com/archives/security-announce/2013/Jun/msg00000.html vendor-advisoryx_refsource_APPLE
- http://lists.fedoraproject.org/pipermail/package-announce/2012-April/079149.html vendor-advisoryx_refsource_FEDORA
- http://lists.fedoraproject.org/pipermail/package-announce/2012-April/079299.html vendor-advisoryx_refsource_FEDORA
- http://lists.fedoraproject.org/pipermail/package-announce/2012-May/080176.html vendor-advisoryx_refsource_FEDORA
- http://lists.fedoraproject.org/pipermail/package-announce/2012-November/092905.html vendor-advisoryx_refsource_FEDORA
- http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00014.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00015.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00007.html vendor-advisoryx_refsource_SUSE
- http://marc.info/?l=bugtraq&m=133728068926468&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=133951357207000&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=134039053214295&w=2 vendor-advisoryx_refsource_HP
- http://osvdb.org/81223 vdb-entryx_refsource_OSVDB
- http://rhn.redhat.com/errata/RHSA-2012-0518.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2012-0522.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2012-1306.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2012-1307.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2012-1308.html vendor-advisoryx_refsource_REDHAT
- http://secunia.com/advisories/48847 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/48895 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/48899 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/48942 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/48999 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/57353 third-party-advisoryx_refsource_SECUNIA
- http://support.apple.com/kb/HT5784 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004564 x_refsource_CONFIRM
- http://www.collax.com/produkte/AllinOne-server-for-small-businesses#id2565578 x_refsource_CONFIRM
- http://www.debian.org/security/2012/dsa-2454 vendor-advisoryx_refsource_DEBIAN
- http://www.exploit-db.com/exploits/18756 exploitx_refsource_EXPLOIT-DB
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:060 vendor-advisoryx_refsource_MANDRIVA
- http://www.openssl.org/news/secadv_20120419.txt x_refsource_CONFIRMVendor Advisory
- http://www.securityfocus.com/bid/53158 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id?1026957 vdb-entryx_refsource_SECTRACK
- http://www.ubuntu.com/usn/USN-1424-1 vendor-advisoryx_refsource_UBUNTU
- https://access.redhat.com/security/cve/CVE-2012-2110 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=814185 Issue Tracking
- https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c03839862 vendor-advisoryx_refsource_HP
- https://kb.juniper.net/KB27376 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2012-2110
- https://www.cve.org/CVERecord?id=CVE-2012-2110
Change history (0)
No recorded changes yet.