CVE-2012-0027: Medium severity OpenSSL OpenSSL vulnerability
The GOST ENGINE in OpenSSL before 1.0.0f does not properly handle invalid parameters for the GOST block cipher, which allows remote attackers to cause a denial of service (daemon crash) via crafted data from a TLS client.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0027?
CVE-2012-0027 has a severity rating that indicates it can lead to a denial of service due to the inability of OpenSSL to properly handle invalid parameters.
How do I fix CVE-2012-0027?
To fix CVE-2012-0027, upgrade to OpenSSL version 1.0.0f or later that includes fixes for the vulnerability.
Which versions of OpenSSL are affected by CVE-2012-0027?
CVE-2012-0027 affects OpenSSL versions prior to 1.0.0f, including 0.9.1c, 0.9.2b, and multiple versions up to 1.0.0e.
What kind of attack does CVE-2012-0027 enable?
CVE-2012-0027 enables remote attackers to execute a denial of service attack that causes the daemon to crash.
Is CVE-2012-0027 associated with TLS clients?
Yes, CVE-2012-0027 can be triggered by crafted data sent from a TLS client, exploiting the vulnerability in the GOST ENGINE.