Security-X

Forum Security-X => News => Discussion démarrée par: igor51 le avril 26, 2012, 00:02:24

Titre: [ThreatPost]OpenSSL Releases New Fix for CVE-2012-2110 ASN1 Bug
Posté par: igor51 le avril 26, 2012, 00:02:24
OpenSSL Releases New Fix for CVE-2012-2110 ASN1 Bug

<p>The OpenSSL developers have had to re-release the fix for a serious vulnerability in the software's ASN.1 implementation that could allow an attacker to cause a denial of service or potentially run arbitrary code on a remote machine. The updated fix only applies to version 0.9.8v; all of the other previously affected versions are already protected with the existing patch.</p><p><a href="http://threatpost.com/en_us/blogs/openssl-releases-new-fix-cve-2012-2110-asn1-bug-042412" target="_blank">read more</a></p>
Source: OpenSSL Releases New Fix for CVE-2012-2110 ASN1 Bug (http://threatpost.com/en_us/blogs/openssl-releases-new-fix-cve-2012-2110-asn1-bug-042412)