PublicDateAtUSN: 2012-01-05 Candidate: CVE-2011-4577 PublicDate: 2012-01-06 01:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4577 http://www.openssl.org/news/secadv_20120104.txt https://ubuntu.com/security/notices/USN-1357-1 Description: OpenSSL before 0.9.8s and 1.x before 1.0.0f, when RFC 3779 support is enabled, allows remote attackers to cause a denial of service (assertion failure) via an X.509 certificate containing certificate-extension data associated with (1) IP address blocks or (2) Autonomous System (AS) identifiers. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Andrew Chi Assigned-to: sbeattie CVSS: Patches_openssl: upstream: http://cvs.openssl.org/chngview?cn=21937 upstream_openssl: released (0.9.8s,1.0.0f) hardy_openssl: released (0.9.8g-4ubuntu3.15) lucid_openssl: released (0.9.8k-7ubuntu8.8) maverick_openssl: released (0.9.8o-1ubuntu4.6) natty_openssl: released (0.9.8o-5ubuntu1.2) oneiric_openssl: released (1.0.0e-2ubuntu4.2) devel_openssl: not-affected (1.0.0g-1ubuntu1) Patches_openssl098: upstream: http://cvs.openssl.org/chngview?cn=21924 upstream_openssl098: released (0.9.8s) hardy_openssl098: DNE lucid_openssl098: DNE maverick_openssl098: DNE natty_openssl098: DNE oneiric_openssl098: released (0.9.8o-7ubuntu1.2) devel_openssl098: released (0.9.8o-7ubuntu3.1)