CVE-2011-4109

Priority
Medium
Description
Double free vulnerability in OpenSSL 0.9.8 before 0.9.8s, when
X509_V_FLAG_POLICY_CHECK is enabled, allows remote attackers to have an
unspecified impact by triggering failure of a policy check.
References
Notes
mdeslaur> 1.0.0 is not affected
Assigned-to
sbeattie
Package
Upstream:released (0.9.8s)
Ubuntu 8.04 LTS (Hardy Heron):DNE
Ubuntu 10.04 LTS (Lucid Lynx):DNE
Ubuntu 11.04 (Natty Narwhal):DNE
Ubuntu 11.10 (Oneiric Ocelot):released (0.9.8o-7ubuntu1.2)
Ubuntu 12.04 LTS (Precise Pangolin):released (0.9.8o-7ubuntu3.1)
Package
Upstream:released (0.9.8s)
Ubuntu 8.04 LTS (Hardy Heron):released (0.9.8g-4ubuntu3.15)
Ubuntu 10.04 LTS (Lucid Lynx):released (0.9.8k-7ubuntu8.8)
Ubuntu 11.04 (Natty Narwhal):released (0.9.8o-5ubuntu1.2)
Ubuntu 11.10 (Oneiric Ocelot):not-affected (1.0.0e-2ubuntu4)
Ubuntu 12.04 LTS (Precise Pangolin):not-affected (1.0.0e-2ubuntu4)
More Information

Valid XHTML 1.0 Strict

Updated: 2012-06-01 15:22:30 UTC (commit 5347)