|
Message-Id: <201202271542.45184.mweckbecker@suse.de> Date: Mon, 27 Feb 2012 15:42:44 +0100 From: Matthias Weckbecker <mweckbecker@...e.de> To: oss-security@...ts.openwall.com Subject: CVE request: openssl: null pointer dereference issue Hi Kurt, Steve, vendors, bad S/MIME messages with crafted MIME headers can result in a NULL pointer dereference in openssl's ans1 parser, https://bugzilla.novell.com/show_bug.cgi?id=748738 http://www.mail-archive.com/openssl-dev@openssl.org/msg30305.html http://cvs.openssl.org/chngview?cn=22144 Does it qualify for a CVE? Thanks, Matthias -- Matthias Weckbecker, Junior Security Engineer, SUSE Security Team SUSE LINUX Products GmbH, Maxfeldstr. 5, D-90409 Nuernberg, Germany Tel: +49-911-74053-0; http://suse.com/ SUSE LINUX Products GmbH, GF: Jeff Hawn, HRB 16746 (AG Nuernberg)
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.