CVE-2012-0027: OpenSSL

Medium severity, CVSS 5.0. EPSS: 4.8% chance of exploitation in the next 30 days.

The GOST ENGINE in OpenSSL before 1.0.0f does not properly handle invalid parameters for the GOST block cipher, which allows remote attackers to cause a denial of service (daemon crash) via crafted data from a TLS client.

Affected products

  • OpenSSL OpenSSL: up to and including 1.0.0e; version 0.9.1c only; version 0.9.2b only; version 0.9.3 only; version 0.9.3a only; version 0.9.4 only; …

Published 2012-01-06. Last modified 2026-06-16.