CVE-2012-2110: OpenSSL

High severity, CVSS 7.5. EPSS: 47.9% chance of exploitation in the next 30 days.

The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in OpenSSL before 0.9.8v, 1.0.0 before 1.0.0i, and 1.0.1 before 1.0.1a does not properly interpret integer data, which allows remote attackers to conduct buffer overflow attacks, and cause a denial of service (memory corruption) or possibly have unspecified other impact, via crafted DER data, as demonstrated by an X.509 certificate or an RSA public key.

Affected products

  • OpenSSL OpenSSL: version 1.0.0 only; version 1.0.0a only; version 1.0.0b only; version 1.0.0c only; version 1.0.0d only; version 1.0.0e only; …
  • Red Hat OpenSSL: version 0.9.6-15 only; version 0.9.6b-3 only; version 0.9.7a-2 only

Published 2012-04-19. Last modified 2026-06-16.