PublicDateAtUSN: 2012-01-05 Candidate: CVE-2011-4109 PublicDate: 2012-01-06 01:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4109 http://www.openssl.org/news/secadv_20120104.txt https://ubuntu.com/security/notices/USN-1357-1 Description: Double free vulnerability in OpenSSL 0.9.8 before 0.9.8s, when X509_V_FLAG_POLICY_CHECK is enabled, allows remote attackers to have an unspecified impact by triggering failure of a policy check. Ubuntu-Description: Notes: mdeslaur> 1.0.0 is not affected Bugs: Priority: medium Discovered-by: Ben Laurie Assigned-to: sbeattie CVSS: Patches_openssl: upstream_openssl: released (0.9.8s) hardy_openssl: released (0.9.8g-4ubuntu3.15) lucid_openssl: released (0.9.8k-7ubuntu8.8) maverick_openssl: released (0.9.8o-1ubuntu4.6) natty_openssl: released (0.9.8o-5ubuntu1.2) oneiric_openssl: not-affected (1.0.0e-2ubuntu4) devel_openssl: not-affected (1.0.0e-2ubuntu4) Patches_openssl098: upstream_openssl098: released (0.9.8s) hardy_openssl098: DNE lucid_openssl098: DNE maverick_openssl098: DNE natty_openssl098: DNE oneiric_openssl098: released (0.9.8o-7ubuntu1.2) devel_openssl098: released (0.9.8o-7ubuntu3.1)