5
CVSSv2

CVE-2012-2686

Published: 08/02/2013 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 540
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

crypto/evp/e_aes_cbc_hmac_sha1.c in the AES-NI functionality in the TLS 1.1 and 1.2 implementations in OpenSSL 1.0.1 prior to 1.0.1d allows remote malicious users to cause a denial of service (application crash) via crafted CBC data.

Vulnerable Product Search on Vulmon Subscribe to Product

openssl openssl 1.0.1c

openssl openssl 1.0.1a

openssl openssl 1.0.1b

openssl openssl 1.0.1

Vendor Advisories

Debian Bug report logs - #704114 asterisk: asterisk security advisories: AST-2013-001 / AST-2013-002 / AST-2013-003 Package: asterisk; Maintainer for asterisk is Debian VoIP Team <pkg-voip-maintainers@listsaliothdebianorg>; Source for asterisk is src:asterisk (PTS, buildd, popcon) Reported by: Salvatore Bonaccorso <car ...
Debian Bug report logs - #697230 asterisk: Two security issues: AST-2012-014 / AST-2012-015 Package: asterisk; Maintainer for asterisk is Debian VoIP Team <pkg-voip-maintainers@listsaliothdebianorg>; Source for asterisk is src:asterisk (PTS, buildd, popcon) Reported by: Salvatore Bonaccorso <carnil@debianorg> Dat ...
Debian Bug report logs - #699889 several issues in Security Advisory 5 Feb 2013 Package: openssl; Maintainer for openssl is Debian OpenSSL Team <pkg-openssl-devel@listsaliothdebianorg>; Source for openssl is src:openssl (PTS, buildd, popcon) Reported by: Thijs Kinkhorst <thijs@debianorg> Date: Wed, 6 Feb 2013 11 ...
Several security issues were fixed in OpenSSL ...
Several security issues were fixed in OpenSSL ...
USN-1732-1 introduced a regression in OpenSSL ...