Re: ASN1 BIO vulnerability (CVE-2012-2110)

2012-05-03 Thread HankScorpio
Where can I see a list of functions affected by this bug? HankScorpio wrote: > > Hi, > > I'm running a 0.9.8g version of the OpenSSL to verify some data. > > I received an email related to a vulnerability of OpenSSL, basically says: > "A potentially exp

ASN1 BIO vulnerability (CVE-2012-2110)

2012-04-24 Thread HankScorpio
Hi, I'm running a 0.9.8g version of the OpenSSL to verify some data. I received an email related to a vulnerability of OpenSSL, basically says: "A potentially exploitable vulnerability has been discovered in the OpenSSL function asn1_d2i_read_bio." ... "Any application which uses BIO or FILE ba