CVE-2010-0742
published 2010-06-03CVE-2010-0742: The Cryptographic Message Syntax (CMS) implementation in crypto/cms/cms_asn1.c in OpenSSL before 0.9.8o and 1.x before 1.0.0a does not properly handle…
PriorityP346high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
7.83%
94.1th percentile
The Cryptographic Message Syntax (CMS) implementation in crypto/cms/cms_asn1.c in OpenSSL before 0.9.8o and 1.x before 1.0.0a does not properly handle structures that contain OriginatorInfo, which allows context-dependent attackers to modify invalid memory locations or conduct double-free attacks, and possibly execute arbitrary code, via unspecified vectors.
Affected
56 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openssl | < openssl 1.0.0e-1 (bookworm) | openssl 1.0.0e-1 (bookworm) |
| openssl | openssl | <= 0.9.8n | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qm9f-p7c7-h3m4: The Cryptographic Message Syntax (CMS) implementation in crypto/cms/cms_asn1
ghsa_unreviewed·2022-05-02
CVE-2010-0742 [HIGH] GHSA-qm9f-p7c7-h3m4: The Cryptographic Message Syntax (CMS) implementation in crypto/cms/cms_asn1
The Cryptographic Message Syntax (CMS) implementation in crypto/cms/cms_asn1.c in OpenSSL before 0.9.8o and 1.x before 1.0.0a does not properly handle structures that contain OriginatorInfo, which allows context-dependent attackers to modify invalid memory locations or conduct double-free attacks, and possibly execute arbitrary code, via unspecified vectors.
OSV
CVE-2010-0742: The Cryptographic Message Syntax (CMS) implementation in crypto/cms/cms_asn1
osv·2010-06-03·CVSS 7.5
CVE-2010-0742 [HIGH] CVE-2010-0742: The Cryptographic Message Syntax (CMS) implementation in crypto/cms/cms_asn1
The Cryptographic Message Syntax (CMS) implementation in crypto/cms/cms_asn1.c in OpenSSL before 0.9.8o and 1.x before 1.0.0a does not properly handle structures that contain OriginatorInfo, which allows context-dependent attackers to modify invalid memory locations or conduct double-free attacks, and possibly execute arbitrary code, via unspecified vectors.
Red Hat
openssl: invalid ASN1 module definition for CMS
vendor_redhat·2010-06-01·CVSS 7.5
CVE-2010-0742 [HIGH] openssl: invalid ASN1 module definition for CMS
openssl: invalid ASN1 module definition for CMS
The Cryptographic Message Syntax (CMS) implementation in crypto/cms/cms_asn1.c in OpenSSL before 0.9.8o and 1.x before 1.0.0a does not properly handle structures that contain OriginatorInfo, which allows context-dependent attackers to modify invalid memory locations or conduct double-free attacks, and possibly execute arbitrary code, via unspecified vectors.
Statement: Not vulnerable. These issues did not affect the versions of OpenSSL as shipped with Red Hat Enterprise Linux 3, 4, or 5.
Package: openssl (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2010-0742: openssl - The Cryptographic Message Syntax (CMS) implementation in crypto/cms/cms_asn1.c i...
vendor_debian·2010·CVSS 7.5
CVE-2010-0742 [HIGH] CVE-2010-0742: openssl - The Cryptographic Message Syntax (CMS) implementation in crypto/cms/cms_asn1.c i...
The Cryptographic Message Syntax (CMS) implementation in crypto/cms/cms_asn1.c in OpenSSL before 0.9.8o and 1.x before 1.0.0a does not properly handle structures that contain OriginatorInfo, which allows context-dependent attackers to modify invalid memory locations or conduct double-free attacks, and possibly execute arbitrary code, via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 1.0.0e-1)
bullseye: resolved (fixed in 1.0.0e-1)
forky: resolved (fixed in 1.0.0e-1)
sid: resolved (fixed in 1.0.0e-1)
trixie: resolved (fixed in 1.0.0e-1)
Red Hat
/kernel/security/CVE-2006-0742 test cause kernel-xen panic on ia64
vendor_redhat·2007-09-11·CVSS 4.6
CVE-2010-2070 [MEDIUM] /kernel/security/CVE-2006-0742 test cause kernel-xen panic on ia64
/kernel/security/CVE-2006-0742 test cause kernel-xen panic on ia64
arch/ia64/xen/faults.c in Xen 3.4 and 4.0 in Linux kernel 2.6.18, and possibly other kernel versions, when running on IA-64 architectures, allows local users to cause a denial of service and "turn on BE by modifying the user mask of the PSR," as demonstrated via exploitation of CVE-2006-0742.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-0742 openssl: invalid ASN1 module definition for CMS
bugzilla·2010-06-01·CVSS 7.5
CVE-2010-0742 [HIGH] CVE-2010-0742 openssl: invalid ASN1 module definition for CMS
CVE-2010-0742 openssl: invalid ASN1 module definition for CMS
From the upstream advisory [1]:
nvalid ASN1 module definition for CMS.
CMS structures containing OriginatorInfo are mishandled this can write to
invalid memory addresses or free up memory twice
(CVE-2010-0742).
This bug is only present in the CMS code: the older PKCS#7 code is not affected.
CMS is only present in OpenSSL 0.9.8h and later where it is disabled by
default and 1.0.0 where it is enabled by default.
Users of OpenSSL CMS code should update to 0.9.8o or 1.0.0a which contains a
patch to correct this issue.
Thanks to Ronald Moesbergen for reporting this issue.
This has been corrected upstream via:
http://cvs.openssl.org/chngview?cn=19693
[1] http://www.openssl.org/news/secadv_20100601.txt
Discussion:
Statemen
Bugzilla
CVE-2010-0742 openssl: invalid ASN1 module definition for CMS [fedora-all]
bugzilla·2010-06-01·CVSS 7.5
CVE-2010-0742 [HIGH] CVE-2010-0742 openssl: invalid ASN1 module definition for CMS [fedora-all]
CVE-2010-0742 openssl: invalid ASN1 module definition for CMS [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
Forr more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=598738
Please note: this issue affects multipl
http://cvs.openssl.org/chngview?cn=19693http://cvs.openssl.org/filediff?f=openssl/crypto/cms/cms_asn1.c&v1=1.8&v2=1.8.6.1http://marc.info/?l=bugtraq&m=129138643405740&w=2http://rt.openssl.org/Ticket/Display.html?id=2211&user=guest&pass=guesthttp://secunia.com/advisories/40000http://secunia.com/advisories/40024http://secunia.com/advisories/42457http://secunia.com/advisories/42724http://secunia.com/advisories/42733http://secunia.com/advisories/57353http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004564http://www.openssl.org/news/secadv_20100601.txthttp://www.securityfocus.com/bid/40502http://www.vupen.com/english/advisories/2010/1313http://www.vupen.com/english/advisories/2010/3105https://bugzilla.redhat.com/show_bug.cgi?id=598738https://kb.bluecoat.com/index?page=content&id=SA50https://lists.balabit.com/pipermail/syslog-ng-announce/2011-January/000101.htmlhttps://lists.balabit.com/pipermail/syslog-ng-announce/2011-January/000102.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12395http://cvs.openssl.org/chngview?cn=19693http://cvs.openssl.org/filediff?f=openssl/crypto/cms/cms_asn1.c&v1=1.8&v2=1.8.6.1http://marc.info/?l=bugtraq&m=129138643405740&w=2http://rt.openssl.org/Ticket/Display.html?id=2211&user=guest&pass=guesthttp://secunia.com/advisories/40000http://secunia.com/advisories/40024http://secunia.com/advisories/42457http://secunia.com/advisories/42724http://secunia.com/advisories/42733http://secunia.com/advisories/57353http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004564http://www.openssl.org/news/secadv_20100601.txthttp://www.securityfocus.com/bid/40502http://www.vupen.com/english/advisories/2010/1313http://www.vupen.com/english/advisories/2010/3105https://bugzilla.redhat.com/show_bug.cgi?id=598738https://kb.bluecoat.com/index?page=content&id=SA50https://lists.balabit.com/pipermail/syslog-ng-announce/2011-January/000101.htmlhttps://lists.balabit.com/pipermail/syslog-ng-announce/2011-January/000102.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12395
2010-06-03
Published