[openssl] off-by-one buffer overflow
Bug #146270 reported by
disabled.user
This bug report is a duplicate of:
Bug #146269: [openssl security] OpenSSL SSL_get_shared_ciphers() off-by-one buffer overflow.
Edit
Remove
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
openssl (Ubuntu) |
New
|
Undecided
|
Unassigned |
Bug Description
Binary package hint: openssl
Quote from [1]:
"Application details:
OpenSSL is a widely used open source implementation of the
SSL v2/v3 and TLS v1 protocols.
Vulnerability description:
OpenSSL 0.9.7l and 0.9.8d fixed a buffer overflow found in
the SSL_get_
Ormandy and Will Drewry of the Google Security Team.
Although this fix prevented the unlimited overflow of the
buffer, it still allowed an off-by-one buffer overflow to
happen, which could potentially still result in remote code
execution."
References:
[1] http://
[2] http://
To post a comment you must log in.