The Cryptographic Message Syntax (CMS) implementation in crypto/cms/cms_asn1.c in OpenSSL before 0.9.8o and 1.x before 1.0.0a does not properly handle structures that contain OriginatorInfo, which allows context-dependent attackers to modify invalid memory locations or conduct double-free attacks, and possibly execute arbitrary code, via unspecified vectors.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade openssl | Jul 30, 2024 | Jun 3, 2010 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Sep 24, 2015 |
| Gentoo Linux | — | Upgrade dev-libs/openssl. | Oct 30, 2017 | Jun 3, 2010 |
| Hpux | — | Update openssl.OPENSSL-INC to the latest versionUpdate openssl.OPENSSL-CER to the latest versionUpdate openssl.OPENSSL-CONF to the latest versionUpdate openssl.OPENSSL-MAN to the latest versionUpdate openssl.OPENSSL-MIS to the latest versionUpdate openssl.OPENSSL-SRC to the latest versionUpdate openssl.OPENSSL-RUN to the latest versionUpdate openssl.OPENSSL-LIB to the latest versionUpdate openssl.OPENSSL-DOC to the latest versionUpdate openssl.OPENSSL-PVT to the latest versionUpdate openssl.OPENSSL-PRNG to the latest version | Aug 11, 2017 | Jun 3, 2010 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | Sep 16, 2010 | Jun 3, 2010 |
| Oracle_linux | — | Upgrade openssl-develUpgrade openssl-perlUpgrade opensslUpgrade openssl-static | May 13, 2016 | Jun 3, 2010 |
| Suse | — | Upgrade libopenssl1_1-32bitUpgrade libopenssl1_1-hmac-32bitUpgrade libopenssl1_1-hmacUpgrade libopenssl-develUpgrade opensslUpgrade openssl1Upgrade openssl1-docUpgrade libopenssl1_0_0-32bitUpgrade libopenssl1_0_0-hmacUpgrade openssl-docUpgrade libopenssl-1_1-devel-32bitUpgrade openssl-1_0_0-docUpgrade openssl-1_1Upgrade libopenssl1_0_0-hmac-32bitUpgrade openssl-1_0_0Upgrade libopenssl-1_1-develUpgrade libopenssl-1_0_0-develUpgrade libopenssl-fips-providerUpgrade libopenssl1-develUpgrade libopenssl1_1Upgrade libopenssl1_0_0 | Aug 9, 2024 | Jun 28, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub