Is there a fix for CVE-2012-2110
Issue
- CVE-2012-2110 (NVD entry) is an OpenSSL security bug announced on the Full Disclosure mailing list (http://lists.grok.org.uk/pipermail/full-disclosure/2012-April/086585.html) at Thu Apr 19 11:35:22 BST 2012:
asn1_d2i_read_bio in OpenSSL contains multiple integer errors that can cause
memory corruption when parsing encoded ASN.1 data. This error can be exploited
on systems that parse untrusted data, such as X.509 certificates or RSA public
keys.
Is their a Errata released to fix this Vulnerability ?
Environment
- Red Hat Enterprise Linux version 6
- Red Hat Enterprise Linux version 5
- Red Hat Enterprise Linux ES (v. 4 ELS)
- Red Hat Enterprise Linux ES (v. 3 ELS)
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.