Gravità: : Alto
  Identificatori CVE: CVE-2010-0742
  Data notifica: 21 luglio 2015

  Descrizione

The Cryptographic Message Syntax (CMS) implementation in crypto/cms/cms_asn1.c in OpenSSL before 0.9.8o and 1.x before 1.0.0a does not properly handle structures that contain OriginatorInfo, which allows context-dependent attackers to modify invalid memory locations or conduct double-free attacks, and possibly execute arbitrary code, via unspecified vectors.

  Informazioni esposizione:

Apply associated Trend Micro DPI Rules.

  Soluzioni

  Trend Micro Deep Security DPI Rule Number: 1004225
  Trend Micro Deep Security DPI Rule Name: 1004225 - OpenSSL Cryptographic Message Syntax Memory Corruption Vulnerability

  Software e versione interessati:

  • OpenSSL OpenSSL 0.9.1c
  • OpenSSL OpenSSL 0.9.2b
  • OpenSSL OpenSSL 0.9.3
  • OpenSSL OpenSSL 0.9.3a
  • OpenSSL OpenSSL 0.9.4
  • OpenSSL OpenSSL 0.9.5
  • OpenSSL OpenSSL 0.9.5a
  • OpenSSL OpenSSL 0.9.6
  • OpenSSL OpenSSL 0.9.6a
  • OpenSSL OpenSSL 0.9.6b
  • OpenSSL OpenSSL 0.9.6c
  • OpenSSL OpenSSL 0.9.6d
  • OpenSSL OpenSSL 0.9.6e
  • OpenSSL OpenSSL 0.9.6f
  • OpenSSL OpenSSL 0.9.6g
  • OpenSSL OpenSSL 0.9.6h
  • OpenSSL OpenSSL 0.9.6i
  • OpenSSL OpenSSL 0.9.6j
  • OpenSSL OpenSSL 0.9.6k
  • OpenSSL OpenSSL 0.9.6l
  • OpenSSL OpenSSL 0.9.6m
  • OpenSSL OpenSSL 0.9.7
  • OpenSSL OpenSSL 0.9.7a
  • OpenSSL OpenSSL 0.9.7b
  • OpenSSL OpenSSL 0.9.7c
  • OpenSSL OpenSSL 0.9.7d
  • OpenSSL OpenSSL 0.9.7e
  • OpenSSL OpenSSL 0.9.7f
  • OpenSSL OpenSSL 0.9.7g
  • OpenSSL OpenSSL 0.9.7h
  • OpenSSL OpenSSL 0.9.7i
  • OpenSSL OpenSSL 0.9.7j
  • OpenSSL OpenSSL 0.9.7k
  • OpenSSL OpenSSL 0.9.7l
  • OpenSSL OpenSSL 0.9.7m
  • OpenSSL OpenSSL 0.9.8
  • OpenSSL OpenSSL 0.9.8a
  • OpenSSL OpenSSL 0.9.8b
  • OpenSSL OpenSSL 0.9.8c
  • OpenSSL OpenSSL 0.9.8d
  • OpenSSL OpenSSL 0.9.8e
  • OpenSSL OpenSSL 0.9.8f
  • OpenSSL OpenSSL 0.9.8g
  • OpenSSL OpenSSL 0.9.8h
  • OpenSSL OpenSSL 0.9.8i
  • OpenSSL OpenSSL 0.9.8j
  • OpenSSL OpenSSL 0.9.8k
  • OpenSSL OpenSSL 0.9.8l
  • OpenSSL OpenSSL 0.9.8m
  • OpenSSL OpenSSL 0.9.8n
  • OpenSSL OpenSSL 1.0.0