CVE-2012-0884Openssl vulnerability

CWE-31013 documents9 sources
Severity
5.0MEDIUMNVD
EPSS
2.8%
top 13.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 13
Latest updateMay 1

Description

The implementation of Cryptographic Message Syntax (CMS) and PKCS #7 in OpenSSL before 0.9.8u and 1.x before 1.0.0h does not properly restrict certain oracle behavior, which makes it easier for context-dependent attackers to decrypt data via a Million Message Attack (MMA) adaptive chosen ciphertext attack.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

debiandebian/openssl< openssl 1.0.0h-1 (bookworm)
Debianopenssl/openssl< 1.0.0h-1+3
NVDopenssl/openssl0.9.8t+65

🔴Vulnerability Details

2
GHSA
GHSA-wwwj-58hm-mxm3: The implementation of Cryptographic Message Syntax (CMS) and PKCS #7 in OpenSSL before 02022-05-14
OSV
CVE-2012-0884: The implementation of Cryptographic Message Syntax (CMS) and PKCS #7 in OpenSSL before 02012-03-13

📋Vendor Advisories

4
BSD
FreeBSD-SA-12:01.openssl: OpenSSL multiple vulnerabilities2012-05-30
Ubuntu
OpenSSL vulnerabilities2012-05-24
Red Hat
openssl: CMS and PKCS#7 Bleichenbacher attack2012-03-12
Debian
CVE-2012-0884: openssl - The implementation of Cryptographic Message Syntax (CMS) and PKCS #7 in OpenSSL ...2012

📄Research Papers

2
arXiv
Graphene: Infrastructure Security Posture Analysis with AI-generated Attack Graphs2024-05-01
arXiv
CEBin: A Cost-Effective Framework for Large-Scale Binary Code Similarity Detection2024-02-29

💬Community

4
Bugzilla
CVE-2012-0884 openssl: CMS and PKCS#7 Bleichenbacher attack2012-03-13
Bugzilla
CVE-2012-1165 CVE-2012-0884 openssl various flaws [fedora-all]2012-03-13
Bugzilla
CVE-2012-1165 CVE-2012-0884 mingw32-openssl various flaws [epel-5]2012-03-13
Bugzilla
CVE-2012-1165 CVE-2012-0884 mingw32-openssl various flaws [fedora-all]2012-03-13