V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2012-2333
DEB
MediumConfirmedExploit available

Integer underflow in OpenSSL before 0.9.8x, 1.0.0 before 1.0.0j, and 1.0.1 before 1.0.1c, when TLS 1.1, TLS 1.2, or DTLS is used with CBC e…

CVSS
5.0
Medium
EPSS
0.28
p97
Published
2012-01-01
Updated
2012-01-01
Description

Integer underflow in OpenSSL before 0.9.8x, 1.0.0 before 1.0.0j, and 1.0.1 before 1.0.1c, when TLS 1.1, TLS 1.2, or DTLS is used with CBC encryption, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted TLS packet that is not properly handled during a certain explicit IV calculation.

Tags · CWE
CWE-189
CWE-190
CAPEC-92
Affected products
Openssl ≤ 0.9.8wOpenssl
CVSS vector
AV:N/AC:L/Au:N/C:N/I:N/A:P
Timeline
2012-01-01
Published
2012-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Authentication
Au: N
None (N)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: N
None (N)
Availability Impact
A: P
Partial
Exploit indicators
EPSS
0.282 · p97
Known exploited (KEV)
No
Known exploits — Сканер-ВС
18756
exploitdb · https://www.exploit-db.com/exploits/18756
Enterprise
Affected products
ProductVendorStatus
opensslTracked
opensslTracked
opensslTracked
opensslTracked
opensslTracked
openssl098Tracked
openssl*Tracked
openssl*Tracked
openssl*Tracked
Source databases
DEB
CVE
RED
UBU
Related vulnerabilities