CVE-2012-0027 Information
Feb 14, 2021
cve
Description
The GOST ENGINE in OpenSSL before 1.0.0f does not properly handle invalid parameters for the GOST block cipher which allows remote attackers to cause a denial of service (daemon crash) via crafted data from a TLS client.
Reference
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03360041 http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00017.html http://osvdb.org/78191 http://secunia.com/advisories/57353 http://www.mandriva.com/security/advisories?name=MDVSA-2012:007 http://www.openssl.org/news/secadv_20120104.txt http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004564
Share on: