Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Mon, 27 Feb 2012 15:42:44 +0100
From: Matthias Weckbecker <>
Subject: CVE request: openssl: null pointer dereference issue

Hi Kurt, Steve, vendors,

bad S/MIME messages with crafted MIME headers can result in a NULL pointer 
dereference in openssl's ans1 parser,

Does it qualify for a CVE?

Thanks, Matthias

Matthias Weckbecker, Junior Security Engineer, SUSE Security Team
SUSE LINUX Products GmbH, Maxfeldstr. 5, D-90409 Nuernberg, Germany
Tel: +49-911-74053-0;
SUSE LINUX Products GmbH, GF: Jeff Hawn, HRB 16746 (AG Nuernberg) 

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Powered by Openwall GNU/*/Linux - Powered by OpenVZ