CVE Vulnerabilities

CVE-2012-0884

Published: Mar 13, 2012 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
2.6 LOW
AV:N/AC:H/Au:N/C:P/I:N/A:N
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

The implementation of Cryptographic Message Syntax (CMS) and PKCS #7 in OpenSSL before 0.9.8u and 1.x before 1.0.0h does not properly restrict certain oracle behavior, which makes it easier for context-dependent attackers to decrypt data via a Million Message Attack (MMA) adaptive chosen ciphertext attack.

Affected Software

NameVendorStart VersionEnd Version
OpensslOpenssl*0.9.8t (including)
OpensslOpenssl0.9.0b (including)0.9.0b (including)
OpensslOpenssl0.9.1b (including)0.9.1b (including)
OpensslOpenssl0.9.1c (including)0.9.1c (including)
OpensslOpenssl0.9.2b (including)0.9.2b (including)
OpensslOpenssl0.9.3 (including)0.9.3 (including)
OpensslOpenssl0.9.3a (including)0.9.3a (including)
OpensslOpenssl0.9.4 (including)0.9.4 (including)
OpensslOpenssl0.9.5 (including)0.9.5 (including)
OpensslOpenssl0.9.5a (including)0.9.5a (including)
OpensslOpenssl0.9.6 (including)0.9.6 (including)
OpensslOpenssl0.9.6a (including)0.9.6a (including)
OpensslOpenssl0.9.6b (including)0.9.6b (including)
OpensslOpenssl0.9.6c (including)0.9.6c (including)
OpensslOpenssl0.9.6d (including)0.9.6d (including)
OpensslOpenssl0.9.6e (including)0.9.6e (including)
OpensslOpenssl0.9.6f (including)0.9.6f (including)
OpensslOpenssl0.9.6g (including)0.9.6g (including)
OpensslOpenssl0.9.6h (including)0.9.6h (including)
OpensslOpenssl0.9.6i (including)0.9.6i (including)
OpensslOpenssl0.9.6j (including)0.9.6j (including)
OpensslOpenssl0.9.6k (including)0.9.6k (including)
OpensslOpenssl0.9.6l (including)0.9.6l (including)
OpensslOpenssl0.9.6m (including)0.9.6m (including)
OpensslOpenssl0.9.7 (including)0.9.7 (including)
OpensslOpenssl0.9.7a (including)0.9.7a (including)
OpensslOpenssl0.9.7b (including)0.9.7b (including)
OpensslOpenssl0.9.7c (including)0.9.7c (including)
OpensslOpenssl0.9.7d (including)0.9.7d (including)
OpensslOpenssl0.9.7e (including)0.9.7e (including)
OpensslOpenssl0.9.7f (including)0.9.7f (including)
OpensslOpenssl0.9.7g (including)0.9.7g (including)
OpensslOpenssl0.9.7h (including)0.9.7h (including)
OpensslOpenssl0.9.7i (including)0.9.7i (including)
OpensslOpenssl0.9.7j (including)0.9.7j (including)
OpensslOpenssl0.9.7k (including)0.9.7k (including)
OpensslOpenssl0.9.7l (including)0.9.7l (including)
OpensslOpenssl0.9.7m (including)0.9.7m (including)
OpensslOpenssl0.9.8 (including)0.9.8 (including)
OpensslOpenssl0.9.8a (including)0.9.8a (including)
OpensslOpenssl0.9.8b (including)0.9.8b (including)
OpensslOpenssl0.9.8c (including)0.9.8c (including)
OpensslOpenssl0.9.8d (including)0.9.8d (including)
OpensslOpenssl0.9.8e (including)0.9.8e (including)
OpensslOpenssl0.9.8f (including)0.9.8f (including)
OpensslOpenssl0.9.8g (including)0.9.8g (including)
OpensslOpenssl0.9.8h (including)0.9.8h (including)
OpensslOpenssl0.9.8i (including)0.9.8i (including)
OpensslOpenssl0.9.8j (including)0.9.8j (including)
OpensslOpenssl0.9.8k (including)0.9.8k (including)
OpensslOpenssl0.9.8l (including)0.9.8l (including)
OpensslOpenssl0.9.8m (including)0.9.8m (including)
OpensslOpenssl0.9.8n (including)0.9.8n (including)
OpensslOpenssl0.9.8o (including)0.9.8o (including)
OpensslOpenssl0.9.8p (including)0.9.8p (including)
OpensslOpenssl0.9.8q (including)0.9.8q (including)
OpensslOpenssl0.9.8r (including)0.9.8r (including)
OpensslOpenssl0.9.8s (including)0.9.8s (including)
OpensslOpenssl1.0.0 (including)1.0.0 (including)
OpensslOpenssl1.0.0a (including)1.0.0a (including)
OpensslOpenssl1.0.0b (including)1.0.0b (including)
OpensslOpenssl1.0.0c (including)1.0.0c (including)
OpensslOpenssl1.0.0d (including)1.0.0d (including)
OpensslOpenssl1.0.0e (including)1.0.0e (including)
OpensslOpenssl1.0.0f (including)1.0.0f (including)
OpensslOpenssl1.0.0g (including)1.0.0g (including)
Red Hat Enterprise Linux 5RedHatopenssl-0:0.9.8e-22.el5_8.1*
Red Hat Enterprise Linux 6RedHatopenssl-0:1.0.0-20.el6_2.3*
Red Hat JBoss Enterprise Application Platform 5.1RedHat*
Red Hat JBoss Enterprise Application Platform 6.0RedHat*
Red Hat JBoss Web Server 1.0RedHat*
OpensslUbuntuhardy*
OpensslUbuntulucid*
OpensslUbuntumaverick*
OpensslUbuntunatty*
OpensslUbuntuoneiric*
OpensslUbuntuupstream*
Openssl098Ubuntudevel*
Openssl098Ubuntuoneiric*
Openssl098Ubuntuprecise*
Openssl098Ubuntuquantal*
Openssl098Ubunturaring*
Openssl098Ubuntusaucy*
Openssl098Ubuntutrusty*

References