English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

OpenSSL TLS Packet Parsing Integer Underflow Denial of Service Vulnerability


Secunia ID

SA49116

CVE-ID

CVE-2012-2333

Release Date

11 May 2012

Last Change

14 May 2012

Criticality

Moderately Critical

Solution Status

Vendor Patch

Software

OpenSSL 0.x
OpenSSL 1.x

Where

From remote

Impact
DoS (Denial of Service)

This includes vulnerabilities ranging from excessive resource consumption (e.g. causing a system to use a lot of memory) to crashing an application or an entire system.

Description

A vulnerability has been reported in OpenSSL, which can be exploited by malicious people to cause a DoS (Denial of Service) of the application using the library.

The vulnerability is caused due to an integer underflow error within the parsing of TLS record length of Datagram Transport Layer Security (DTLS) packets using CBC encryption mode, which can be exploited to cause a crash.

The vulnerability is reported in versions prior to 1.0.1c, 1.0.0j, and 0.9.8x.

Solution

Update to version 1.0.1c, 1.0.0j, or 0.9.8x.

Reported by

CERT-FI credits Codenomicon.

Original Advisory

http://www.openssl.org/news/secadv_20120510.txt

CERT-FI (FICORA #641549):
http://www.cert.fi/en/reports/2012/vulnerability641549.html