oss-sec mailing list archives

CVE request: openssl: null pointer dereference issue


From: Matthias Weckbecker <mweckbecker () suse de>
Date: Mon, 27 Feb 2012 15:42:44 +0100

Hi Kurt, Steve, vendors,

bad S/MIME messages with crafted MIME headers can result in a NULL pointer 
dereference in openssl's ans1 parser,

 https://bugzilla.novell.com/show_bug.cgi?id=748738
 http://www.mail-archive.com/openssl-dev () openssl org/msg30305.html
 http://cvs.openssl.org/chngview?cn=22144

Does it qualify for a CVE?

Thanks, Matthias

-- 
Matthias Weckbecker, Junior Security Engineer, SUSE Security Team
SUSE LINUX Products GmbH, Maxfeldstr. 5, D-90409 Nuernberg, Germany
Tel: +49-911-74053-0;  http://suse.com/
SUSE LINUX Products GmbH, GF: Jeff Hawn, HRB 16746 (AG Nuernberg) 


Current thread: