Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Mon, 27 Feb 2012 15:42:44 +0100
From: Matthias Weckbecker <mweckbecker@...e.de>
To: oss-security@...ts.openwall.com
Subject: CVE request: openssl: null pointer dereference issue

Hi Kurt, Steve, vendors,

bad S/MIME messages with crafted MIME headers can result in a NULL pointer 
dereference in openssl's ans1 parser,

 https://bugzilla.novell.com/show_bug.cgi?id=748738
 http://www.mail-archive.com/openssl-dev@openssl.org/msg30305.html
 http://cvs.openssl.org/chngview?cn=22144

Does it qualify for a CVE?

Thanks, Matthias

-- 
Matthias Weckbecker, Junior Security Engineer, SUSE Security Team
SUSE LINUX Products GmbH, Maxfeldstr. 5, D-90409 Nuernberg, Germany
Tel: +49-911-74053-0;  http://suse.com/
SUSE LINUX Products GmbH, GF: Jeff Hawn, HRB 16746 (AG Nuernberg) 

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.