The ASN1_TYPE_cmp function in crypto/asn1/a_type.c in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a does not properly perform boolean-type comparisons, which allows remote attackers to cause a denial of service (invalid read operation and application crash) via a crafted X.509 certificate to an endpoint that uses the certificate-verification feature.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Openssl | Openssl | * | 0.9.8ze (including) |
Openssl | Openssl | 1.0.0 (including) | 1.0.0 (including) |
Openssl | Openssl | 1.0.0a (including) | 1.0.0a (including) |
Openssl | Openssl | 1.0.0b (including) | 1.0.0b (including) |
Openssl | Openssl | 1.0.0c (including) | 1.0.0c (including) |
Openssl | Openssl | 1.0.0d (including) | 1.0.0d (including) |
Openssl | Openssl | 1.0.0e (including) | 1.0.0e (including) |
Openssl | Openssl | 1.0.0f (including) | 1.0.0f (including) |
Openssl | Openssl | 1.0.0g (including) | 1.0.0g (including) |
Openssl | Openssl | 1.0.0h (including) | 1.0.0h (including) |
Openssl | Openssl | 1.0.0i (including) | 1.0.0i (including) |
Openssl | Openssl | 1.0.0j (including) | 1.0.0j (including) |
Openssl | Openssl | 1.0.0k (including) | 1.0.0k (including) |
Openssl | Openssl | 1.0.0l (including) | 1.0.0l (including) |
Openssl | Openssl | 1.0.0m (including) | 1.0.0m (including) |
Openssl | Openssl | 1.0.0n (including) | 1.0.0n (including) |
Openssl | Openssl | 1.0.0o (including) | 1.0.0o (including) |
Openssl | Openssl | 1.0.0p (including) | 1.0.0p (including) |
Openssl | Openssl | 1.0.0q (including) | 1.0.0q (including) |
Openssl | Openssl | 1.0.1 (including) | 1.0.1 (including) |
Openssl | Openssl | 1.0.1a (including) | 1.0.1a (including) |
Openssl | Openssl | 1.0.1b (including) | 1.0.1b (including) |
Openssl | Openssl | 1.0.1c (including) | 1.0.1c (including) |
Openssl | Openssl | 1.0.1d (including) | 1.0.1d (including) |
Openssl | Openssl | 1.0.1e (including) | 1.0.1e (including) |
Openssl | Openssl | 1.0.1f (including) | 1.0.1f (including) |
Openssl | Openssl | 1.0.1g (including) | 1.0.1g (including) |
Openssl | Openssl | 1.0.1h (including) | 1.0.1h (including) |
Openssl | Openssl | 1.0.1i (including) | 1.0.1i (including) |
Openssl | Openssl | 1.0.1j (including) | 1.0.1j (including) |
Openssl | Openssl | 1.0.1k (including) | 1.0.1k (including) |
Openssl | Openssl | 1.0.1l (including) | 1.0.1l (including) |
Openssl | Openssl | 1.0.2 (including) | 1.0.2 (including) |