OpenSSL Cryptographic Message Syntax Memory Corruption Vulnerability
Publish date: 21 de julio de 2015
Gravedad: High
Identificadores de CVE : CVE-2010-0742
Fecha recomendada: 21 de julio de 2015
Descripción
The Cryptographic Message Syntax (CMS) implementation in crypto/cms/cms_asn1.c in OpenSSL before 0.9.8o and 1.x before 1.0.0a does not properly handle structures that contain OriginatorInfo, which allows context-dependent attackers to modify invalid memory locations or conduct double-free attacks, and possibly execute arbitrary code, via unspecified vectors.
Revelación de la información
Apply associated Trend Micro DPI Rules.
Soluciones
Trend Micro Deep Security DPI Rule Number: 1004225
Trend Micro Deep Security DPI Rule Name: 1004225 - OpenSSL Cryptographic Message Syntax Memory Corruption Vulnerability
Software y versión afectados
- OpenSSL OpenSSL 0.9.1c
- OpenSSL OpenSSL 0.9.2b
- OpenSSL OpenSSL 0.9.3
- OpenSSL OpenSSL 0.9.3a
- OpenSSL OpenSSL 0.9.4
- OpenSSL OpenSSL 0.9.5
- OpenSSL OpenSSL 0.9.5a
- OpenSSL OpenSSL 0.9.6
- OpenSSL OpenSSL 0.9.6a
- OpenSSL OpenSSL 0.9.6b
- OpenSSL OpenSSL 0.9.6c
- OpenSSL OpenSSL 0.9.6d
- OpenSSL OpenSSL 0.9.6e
- OpenSSL OpenSSL 0.9.6f
- OpenSSL OpenSSL 0.9.6g
- OpenSSL OpenSSL 0.9.6h
- OpenSSL OpenSSL 0.9.6i
- OpenSSL OpenSSL 0.9.6j
- OpenSSL OpenSSL 0.9.6k
- OpenSSL OpenSSL 0.9.6l
- OpenSSL OpenSSL 0.9.6m
- OpenSSL OpenSSL 0.9.7
- OpenSSL OpenSSL 0.9.7a
- OpenSSL OpenSSL 0.9.7b
- OpenSSL OpenSSL 0.9.7c
- OpenSSL OpenSSL 0.9.7d
- OpenSSL OpenSSL 0.9.7e
- OpenSSL OpenSSL 0.9.7f
- OpenSSL OpenSSL 0.9.7g
- OpenSSL OpenSSL 0.9.7h
- OpenSSL OpenSSL 0.9.7i
- OpenSSL OpenSSL 0.9.7j
- OpenSSL OpenSSL 0.9.7k
- OpenSSL OpenSSL 0.9.7l
- OpenSSL OpenSSL 0.9.7m
- OpenSSL OpenSSL 0.9.8
- OpenSSL OpenSSL 0.9.8a
- OpenSSL OpenSSL 0.9.8b
- OpenSSL OpenSSL 0.9.8c
- OpenSSL OpenSSL 0.9.8d
- OpenSSL OpenSSL 0.9.8e
- OpenSSL OpenSSL 0.9.8f
- OpenSSL OpenSSL 0.9.8g
- OpenSSL OpenSSL 0.9.8h
- OpenSSL OpenSSL 0.9.8i
- OpenSSL OpenSSL 0.9.8j
- OpenSSL OpenSSL 0.9.8k
- OpenSSL OpenSSL 0.9.8l
- OpenSSL OpenSSL 0.9.8m
- OpenSSL OpenSSL 0.9.8n
- OpenSSL OpenSSL 1.0.0