CVE-2012-1165
published 2012-03-15CVE-2012-1165: The mime_param_cmp function in crypto/asn1/asn_mime.c in OpenSSL before 0.9.8u and 1.x before 1.0.0h allows remote attackers to cause a denial of service (NULL…
PriorityP421medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
6.84%
93.3th percentile
The mime_param_cmp function in crypto/asn1/asn_mime.c in OpenSSL before 0.9.8u and 1.x before 1.0.0h allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted S/MIME message, a different vulnerability than CVE-2006-7250.
Affected
69 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openssl | < openssl 1.0.0h-1 (bookworm) | openssl 1.0.0h-1 (bookworm) |
| openssl | openssl | <= 0.9.8t | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9vv4-xxfm-24ff: The mime_param_cmp function in crypto/asn1/asn_mime
ghsa_unreviewed·2022-05-14·CVSS 5.0
CVE-2012-1165 [MEDIUM] GHSA-9vv4-xxfm-24ff: The mime_param_cmp function in crypto/asn1/asn_mime
The mime_param_cmp function in crypto/asn1/asn_mime.c in OpenSSL before 0.9.8u and 1.x before 1.0.0h allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted S/MIME message, a different vulnerability than CVE-2006-7250.
OSV
CVE-2012-1165: The mime_param_cmp function in crypto/asn1/asn_mime
osv·2012-03-15·CVSS 5.0
CVE-2012-1165 [MEDIUM] CVE-2012-1165: The mime_param_cmp function in crypto/asn1/asn_mime
The mime_param_cmp function in crypto/asn1/asn_mime.c in OpenSSL before 0.9.8u and 1.x before 1.0.0h allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted S/MIME message, a different vulnerability than CVE-2006-7250.
Ubuntu
OpenSSL vulnerabilities
vendor_ubuntu·2012-04-19·CVSS 5.0
CVE-2006-7250 [MEDIUM] OpenSSL vulnerabilities
Title: OpenSSL vulnerabilities
Summary: An application using OpenSSL could be made to crash or run programs if it
opened a specially crafted file.
It was discovered that OpenSSL could be made to dereference a NULL pointer
when processing S/MIME messages. A remote attacker could use this to cause
a denial of service. These issues did not affect Ubuntu 8.04 LTS.
(CVE-2006-7250, CVE-2012-1165)
Tavis Ormandy discovered that OpenSSL did not properly perform bounds
checking when processing DER data via BIO or FILE functions. A remote
attacker could trigger this flaw in services that used SSL to cause a
denial of service or possibly execute arbitrary code with application
privileges. (CVE-2012-2110)
Instructions: After a standard system update you need to reboot your computer to make
all the
Red Hat
openssl: mime_param_cmp NULL dereference crash
vendor_redhat·2012-03-12·CVSS 5.0
CVE-2012-1165 [MEDIUM] CWE-476 openssl: mime_param_cmp NULL dereference crash
openssl: mime_param_cmp NULL dereference crash
The mime_param_cmp function in crypto/asn1/asn_mime.c in OpenSSL before 0.9.8u and 1.x before 1.0.0h allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted S/MIME message, a different vulnerability than CVE-2006-7250.
Package: openssl (Red Hat Enterprise Linux 4) - Will not fix
Package: openssl096b (Red Hat Enterprise Linux 4) - Will not fix
Package: openssl097a (Red Hat Enterprise Linux 5) - Will not fix
Package: openssl098e (Red Hat Enterprise Linux 6) - Will not fix
Package: openssl (Red Hat JBoss Enterprise Web Server 1) - Affected
Debian
CVE-2012-1165: openssl - The mime_param_cmp function in crypto/asn1/asn_mime.c in OpenSSL before 0.9.8u a...
vendor_debian·2012·CVSS 5.0
CVE-2012-1165 [MEDIUM] CVE-2012-1165: openssl - The mime_param_cmp function in crypto/asn1/asn_mime.c in OpenSSL before 0.9.8u a...
The mime_param_cmp function in crypto/asn1/asn_mime.c in OpenSSL before 0.9.8u and 1.x before 1.0.0h allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted S/MIME message, a different vulnerability than CVE-2006-7250.
Scope: local
bookworm: resolved (fixed in 1.0.0h-1)
bullseye: resolved (fixed in 1.0.0h-1)
forky: resolved (fixed in 1.0.0h-1)
sid: resolved (fixed in 1.0.0h-1)
trixie: resolved (fixed in 1.0.0h-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-1165 CVE-2012-0884 openssl various flaws [fedora-all]
bugzilla·2012-03-13·CVSS 5.0
CVE-2012-1165 [MEDIUM] CVE-2012-1165 CVE-2012-0884 openssl various flaws [fedora-all]
CVE-2012-1165 CVE-2012-0884 openssl various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=802489
Bugzilla
CVE-2012-1165 CVE-2012-0884 mingw32-openssl various flaws [epel-5]
bugzilla·2012-03-13·CVSS 5.0
CVE-2012-1165 [MEDIUM] CVE-2012-1165 CVE-2012-0884 mingw32-openssl various flaws [epel-5]
CVE-2012-1165 CVE-2012-0884 mingw32-openssl various flaws [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=802
Bugzilla
CVE-2012-1165 CVE-2012-0884 mingw32-openssl various flaws [fedora-all]
bugzilla·2012-03-13·CVSS 5.0
CVE-2012-1165 [MEDIUM] CVE-2012-1165 CVE-2012-0884 mingw32-openssl various flaws [fedora-all]
CVE-2012-1165 CVE-2012-0884 mingw32-openssl various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs
Bugzilla
CVE-2012-1165 openssl: mime_param_cmp NULL dereference crash
bugzilla·2012-03-12·CVSS 5.0
CVE-2012-1165 [MEDIUM] CVE-2012-1165 openssl: mime_param_cmp NULL dereference crash
CVE-2012-1165 openssl: mime_param_cmp NULL dereference crash
A NULL pointer dereference flaw was found in OpenSSL's mime_param_cmp. A specially crafted S/MIME input headers could cause an application using OpenSSL to crash during S/MIME message verification or decryption.
This is similar to the mime_hdr_cmp issue tracked via bug 798100.
Upstream commit:
http://cvs.openssl.org/chngview?cn=22252
and cn 22243 and 22244 for 0.9.8 and 1.0.0 branch commits
Fixed upstream in versions: 0.9.8u and 1.0.0h
Discussion:
http://www.openwall.com/lists/oss-security/2012/03/12/6
---
Created mingw32-openssl tracking bugs for this issue
Affects: fedora-all [bug 802817]
Affects: epel-5 [bug 802820]
---
Created openssl tracking bugs for this issue
Affects: fedora-all [bug 802816]
---
This issue h
Bugzilla
CVE-2011-2908 CSRF on jmx-console allows invocation of operations on mbeans
bugzilla·2011-08-12·CVSS 6.0
CVE-2011-2908 [MEDIUM] CVE-2011-2908 CSRF on jmx-console allows invocation of operations on mbeans
CVE-2011-2908 CSRF on jmx-console allows invocation of operations on mbeans
The JMX console as shipped with JBoss EAP 5.1.1 is vulnerable to cross-site request forgery (CSRF) attacks. This vulnerability allows an attacker to invoke operations on mbeans via the JMX console.
Discussion:
This issue has been addressed in following products:
JBoss Enterprise SOA Platform 5.3.0
Via RHSA-2012:1152 https://rhn.redhat.com/errata/RHSA-2012-1152.html
---
This issue has been addressed in following products:
JBoss Enterprise BRMS Platform 5.3.0
Via RHSA-2012:1165 https://rhn.redhat.com/errata/RHSA-2012-1165.html
---
This issue has been addressed in following products:
JBoss Enterprise Portal Platform 5.2.2
Via RHSA-2012:1232 https://rhn.redhat.com/errata/RHSA-2012-1232.html
---
This issu
http://cvs.openssl.org/chngview?cn=22252http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03360041http://lists.fedoraproject.org/pipermail/package-announce/2012-April/077086.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-April/077221.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-April/077666.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-November/092905.htmlhttp://marc.info/?l=bugtraq&m=133728068926468&w=2http://marc.info/?l=bugtraq&m=134039053214295&w=2http://rhn.redhat.com/errata/RHSA-2012-0426.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0488.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0531.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1306.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1307.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1308.htmlhttp://secunia.com/advisories/48580http://secunia.com/advisories/48895http://secunia.com/advisories/48899http://www.debian.org/security/2012/dsa-2454http://www.openwall.com/lists/oss-security/2012/03/12/3http://www.openwall.com/lists/oss-security/2012/03/12/6http://www.openwall.com/lists/oss-security/2012/03/12/7http://www.openwall.com/lists/oss-security/2012/03/13/2http://www.securityfocus.com/bid/52764http://www.securitytracker.com/id?1026787http://www.ubuntu.com/usn/USN-1424-1https://downloads.avaya.com/css/P8/documents/100162507http://cvs.openssl.org/chngview?cn=22252http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03360041http://lists.fedoraproject.org/pipermail/package-announce/2012-April/077086.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-April/077221.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-April/077666.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-November/092905.htmlhttp://marc.info/?l=bugtraq&m=133728068926468&w=2http://marc.info/?l=bugtraq&m=134039053214295&w=2http://rhn.redhat.com/errata/RHSA-2012-0426.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0488.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0531.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1306.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1307.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1308.htmlhttp://secunia.com/advisories/48580http://secunia.com/advisories/48895http://secunia.com/advisories/48899http://www.debian.org/security/2012/dsa-2454http://www.openwall.com/lists/oss-security/2012/03/12/3http://www.openwall.com/lists/oss-security/2012/03/12/6http://www.openwall.com/lists/oss-security/2012/03/12/7http://www.openwall.com/lists/oss-security/2012/03/13/2http://www.securityfocus.com/bid/52764http://www.securitytracker.com/id?1026787http://www.ubuntu.com/usn/USN-1424-1https://downloads.avaya.com/css/P8/documents/100162507
2012-03-15
Published