CVE-2012-2333
EPSS 6.8%openssl - integer underflow
發布日:2012/5/14修改日:2026/4/28
描述
Integer underflow in OpenSSL before 0.9.8x, 1.0.0 before 1.0.0j, and 1.0.1 before 1.0.1c, when TLS 1.1, TLS 1.2, or DTLS is used with CBC encryption, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted TLS packet that is not properly handled during a certain explicit IV calculation.
受影響套件(2)
- Debian/opensslfrom 0, < 1.0.1c-1
- Debian/opensslfrom 0, < 0.9.8o-4squeeze13