OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols, as well as a
full-strength, general purpose cryptography library.
Multiple numeric conversion errors, leading to a buffer overflow, were
found in the way OpenSSL parsed ASN.1 (Abstract Syntax Notation One) data
from BIO (OpenSSL’s I/O abstraction) inputs. Specially-crafted DER
(Distinguished Encoding Rules) encoded data read from a file or other BIO
input could cause an application using the OpenSSL library to crash or,
potentially, execute arbitrary code. (CVE-2012-2110)
All OpenSSL users should upgrade to these updated packages, which contain
a backported patch to resolve this issue. For the update to take effect,
all services linked to the OpenSSL library must be restarted, or the system
rebooted.
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
RedHat | 5 | ppc64 | openssl | < 0.9.8e-12.el5_6.9 | openssl-0.9.8e-12.el5_6.9.ppc64.rpm |
RedHat | 5 | ia64 | openssl-perl | < 0.9.8e-12.el5_6.9 | openssl-perl-0.9.8e-12.el5_6.9.ia64.rpm |
RedHat | 6 | s390x | openssl | < 1.0.0-10.el6_1.6 | openssl-1.0.0-10.el6_1.6.s390x.rpm |
RedHat | 6 | ppc64 | openssl-perl | < 1.0.0-10.el6_1.6 | openssl-perl-1.0.0-10.el6_1.6.ppc64.rpm |
RedHat | 6 | ppc | openssl-debuginfo | < 1.0.0-10.el6_1.6 | openssl-debuginfo-1.0.0-10.el6_1.6.ppc.rpm |
RedHat | 4 | ia64 | openssl | < 0.9.7a-43.20.el4 | openssl-0.9.7a-43.20.el4.ia64.rpm |
RedHat | 6 | x86_64 | openssl-debuginfo | < 1.0.0-10.el6_1.6 | openssl-debuginfo-1.0.0-10.el6_1.6.x86_64.rpm |
RedHat | 5 | i386 | openssl-perl | < 0.9.8e-12.el5_6.9 | openssl-perl-0.9.8e-12.el5_6.9.i386.rpm |
RedHat | 5 | s390x | openssl-devel | < 0.9.8e-12.el5_6.9 | openssl-devel-0.9.8e-12.el5_6.9.s390x.rpm |
RedHat | 6 | s390 | openssl-devel | < 1.0.0-10.el6_1.6 | openssl-devel-1.0.0-10.el6_1.6.s390.rpm |