English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

OpenSSL ASN.1 MIME Header Parsing NULL Pointer Dereference Vulnerability


Secunia ID

SA48153

CVE-ID

CVE-2006-7250

Release Date

28 Feb 2012

Last Change

02 Mar 2012

Criticality

Moderately Critical

Solution Status

Vendor Workaround

Software

OpenSSL 0.x
OpenSSL 1.x

Where

From remote

Impact
DoS (Denial of Service)

This includes vulnerabilities ranging from excessive resource consumption (e.g. causing a system to use a lot of memory) to crashing an application or an entire system.

Description

A vulnerability has been reported in OpenSSL, which can be exploited by malicious people to cause a DoS (Denial of Service) of the application using the library.

The vulnerability is caused due to a NULL-pointer dereference error in the "mime_hdr_cmp()" function (crypto/asn1/asn_mime.c) when parsing certain MIME headers and can be exploited to cause a crash.

The vulnerability is reported in versions 0.9.7i, 0.9.8t, and 1.0.0g. Other versions may also be affected.

Solution

Fixed in the CVS repository.

Reported by

Reported by Mats Nilsson to the openssl-dev mailing list.

Original Advisory

Mats Nilsson:
http://marc.info/?l=openssl-dev&m=115685408414194&w=2

OpenSSL:
http://cvs.openssl.org/chngview?cn=22144