CVE-2012-0027
Publication date 5 January 2012
Last updated 24 July 2024
Ubuntu priority
The GOST ENGINE in OpenSSL before 1.0.0f does not properly handle invalid parameters for the GOST block cipher, which allows remote attackers to cause a denial of service (daemon crash) via crafted data from a TLS client.
Status
Package | Ubuntu Release | Status |
---|---|---|
openssl | ||
openssl098 | ||
Notes
References
Related Ubuntu Security Notices (USN)
- USN-1357-1
- OpenSSL vulnerabilities
- 9 February 2012