Back to Database
Status published
Critical
CVE-2011-4109
Double free vulnerability in OpenSSL 0.9.8 before 0.9.8s, when X509_V_FLAG_POLICY_CHECK...
Vulnerability Description
Double free vulnerability in OpenSSL 0.9.8 before 0.9.8s, when X509_V_FLAG_POLICY_CHECK is enabled, allows remote attackers to have an unspecified impact by triggering failure of a policy check.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2011-4109
Credits & Attribution
No credits recorded in the NVD database.
References
- http://secunia.com/advisories/48528
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:006
- http://www.openssl.org/news/secadv_20120104.txt
- http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00018.html
- http://rhn.redhat.com/errata/RHSA-2012-1308.html
- http://rhn.redhat.com/errata/RHSA-2012-1307.html
- http://support.apple.com/kb/HT5784
- http://lists.apple.com/archives/security-announce/2013/Jun/msg00000.html
- http://www.kb.cert.org/vuls/id/737740
- http://marc.info/?l=bugtraq&m=132750648501816&w=2
- https://exchange.xforce.ibmcloud.com/vulnerabilities/72129
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:007
- http://rhn.redhat.com/errata/RHSA-2012-1306.html
- http://marc.info/?l=bugtraq&m=134039053214295&w=2
- http://marc.info/?l=bugtraq&m=134039053214295&w=2
- http://marc.info/?l=bugtraq&m=132750648501816&w=2
- http://www.debian.org/security/2012/dsa-2390
- http://aix.software.ibm.com/aix/efixes/security/openssl_advisory3.asc
More from openssl
View All →CVE-2016-7055
There is a carry propagating bug in the Broadwell-specific Montgomery...
Medium
5.9
CVE-2016-6309
statem/statem.c in OpenSSL 1.1.0a does not consider memory-block movement after...
Critical
9.8
CVE-2016-6308
statem/statem_dtls.c in the DTLS implementation in OpenSSL 1.1.0 before 1.1.0a...
Medium
5.9
CVE-2016-6307
The state-machine implementation in OpenSSL 1.1.0 before 1.1.0a allocates memory...
Medium
5.9
CVE-2016-6306
The certificate parser in OpenSSL before 1.0.1u and 1.0.2 before...
Medium
5.9
Affected Vendor
openssl
View all reports →Affected Software
openssl
Vulnerable Versions:
0.9.8, 0.9.8a, 0.9.8b, 0.9.8c, 0.9.8d, 0.9.8e, 0.9.8f, 0.9.8g, 0.9.8h, 0.9.8i, 0.9.8j, 0.9.8k, 0.9.8l, 0.9.8m, 0.9.8n, 0.9.8o, 0.9.8p, 0.9.8q, 0.9.8r
Timeline
Official Publish:
January 6th, 2012
Last Modified:
August 7th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.