OpenSSL Information for VU#748355

ASN.1 parsing errors exist in implementations of SSL, TLS, S/MIME, PKCS#7 routines

Status

Affected

Vendor Statement

Please see http://www.openssl.org/news/secadv_20020730.txt.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Vendor References

None

Addendum

The OpenSSL team has recently released OpenSSL 0.9.6g to completely remove all known instances of this vulnerability:

ftp://ftp.openssl.org/source/openssl-engine-0.9.6g.tar.gz
ftp://ftp.openssl.org/source/openssl-engine-0.9.6g.tar.gz.asc
ftp://ftp.openssl.org/source/openssl-engine-0.9.6g.tar.gz.md5

If you have feedback, comments, or additional information about this vulnerability, please send us email.