peter bassill · operator
$ cve CVE-2012-2110 JSON

CVE-2012-2110 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 47.9% (pctl 99)

Patch early

A public exploit exists.

Description

The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in OpenSSL before 0.9.8v, 1.0.0 before 1.0.0i, and 1.0.1 before 1.0.1a does not properly interpret integer data, which allows remote attackers to conduct buffer overflow attacks, and cause a denial of service (memory corruption) or possibly have unspecified other impact, via crafted DER data, as demonstrated by an X.509 certificate or an RSA public key.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS47.91% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2012-04-19
Last modified2026-06-16

Affected (2)

VendorProduct
opensslopenssl
redhatopenssl

Public exploits

SourceTitleDate
exploit-dbOpenSSL - ASN1 BIO Memory Corruption2012-04-19

References

→ the Explorer  ·  watch your stack  ·  NVD