CVE-2012-0027
published 2012-01-06CVE-2012-0027: The GOST ENGINE in OpenSSL before 1.0.0f does not properly handle invalid parameters for the GOST block cipher, which allows remote attackers to cause a denial…
PriorityP424medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
4.99%
91.3th percentile
The GOST ENGINE in OpenSSL before 1.0.0f does not properly handle invalid parameters for the GOST block cipher, which allows remote attackers to cause a denial of service (daemon crash) via crafted data from a TLS client.
Affected
66 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openssl | < openssl 1.0.0f-1 (bookworm) | openssl 1.0.0f-1 (bookworm) |
| openssl | openssl | <= 1.0.0e | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
vendor_ubuntu2.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6vgp-r5v2-7gfw: The GOST ENGINE in OpenSSL before 1
ghsa_unreviewed·2022-05-04
CVE-2012-0027 [MEDIUM] GHSA-6vgp-r5v2-7gfw: The GOST ENGINE in OpenSSL before 1
The GOST ENGINE in OpenSSL before 1.0.0f does not properly handle invalid parameters for the GOST block cipher, which allows remote attackers to cause a denial of service (daemon crash) via crafted data from a TLS client.
OSV
CVE-2012-0027: The GOST ENGINE in OpenSSL before 1
osv·2012-01-06·CVSS 5.0
CVE-2012-0027 [MEDIUM] CVE-2012-0027: The GOST ENGINE in OpenSSL before 1
The GOST ENGINE in OpenSSL before 1.0.0f does not properly handle invalid parameters for the GOST block cipher, which allows remote attackers to cause a denial of service (daemon crash) via crafted data from a TLS client.
Ubuntu
OpenSSL vulnerabilities
vendor_ubuntu·2012-02-09·CVSS 2.6
CVE-2012-0027 [LOW] OpenSSL vulnerabilities
Title: OpenSSL vulnerabilities
Summary: Multiple vulnerabilities exist in OpenSSL that could expose
sensitive information or cause applications to crash.
It was discovered that the elliptic curve cryptography (ECC) subsystem
in OpenSSL, when using the Elliptic Curve Digital Signature Algorithm
(ECDSA) for the ECDHE_ECDSA cipher suite, did not properly implement
curves over binary fields. This could allow an attacker to determine
private keys via a timing attack. This issue only affected Ubuntu 8.04
LTS, Ubuntu 10.04 LTS, Ubuntu 10.10 and Ubuntu 11.04. (CVE-2011-1945)
Adam Langley discovered that the ephemeral Elliptic Curve
Diffie-Hellman (ECDH) functionality in OpenSSL did not ensure thread
safety while processing handshake messages from clients. This
could allow a remote attacker to c
Red Hat
openssl: invalid GOST parameters DoS attack
vendor_redhat·2012-01-04·CVSS 5.0
CVE-2012-0027 [MEDIUM] openssl: invalid GOST parameters DoS attack
openssl: invalid GOST parameters DoS attack
The GOST ENGINE in OpenSSL before 1.0.0f does not properly handle invalid parameters for the GOST block cipher, which allows remote attackers to cause a denial of service (daemon crash) via crafted data from a TLS client.
Statement: Not vulnerable. This issue did not affect the versions of openssl as shipped with Red Hat Enterprise Linux 3, 4, 5 and 6, as they did not include GOST engine support.
Package: openssl (Red Hat Enterprise Linux 4) - Not affected
Package: openssl096b (Red Hat Enterprise Linux 4) - Not affected
Package: openssl (Red Hat Enterprise Linux 5) - Not affected
Package: openssl097a (Red Hat Enterprise Linux 5) - Not affected
Package: openssl (Red Hat Enterprise Linux 6) - Not affected
Package: openssl098e (Red Hat Enter
Debian
CVE-2012-0027: openssl - The GOST ENGINE in OpenSSL before 1.0.0f does not properly handle invalid parame...
vendor_debian·2012·CVSS 5.0
CVE-2012-0027 [MEDIUM] CVE-2012-0027: openssl - The GOST ENGINE in OpenSSL before 1.0.0f does not properly handle invalid parame...
The GOST ENGINE in OpenSSL before 1.0.0f does not properly handle invalid parameters for the GOST block cipher, which allows remote attackers to cause a denial of service (daemon crash) via crafted data from a TLS client.
Scope: local
bookworm: resolved (fixed in 1.0.0f-1)
bullseye: resolved (fixed in 1.0.0f-1)
forky: resolved (fixed in 1.0.0f-1)
sid: resolved (fixed in 1.0.0f-1)
trixie: resolved (fixed in 1.0.0f-1)
No detection rules found.
No public exploits indexed.
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03360041http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00017.htmlhttp://osvdb.org/78191http://secunia.com/advisories/57353http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004564http://www.mandriva.com/security/advisories?name=MDVSA-2012:007http://www.openssl.org/news/secadv_20120104.txthttp://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03360041http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00017.htmlhttp://osvdb.org/78191http://secunia.com/advisories/57353http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004564http://www.mandriva.com/security/advisories?name=MDVSA-2012:007http://www.openssl.org/news/secadv_20120104.txt
2012-01-06
Published