CVE-2012-2333 is an integer underflow vulnerability in OpenSSL versions prior to 0.9.8x, 1.0.0j, and 1.0.1c, specifically when TLS 1.1, TLS 1.2, or DTLS is used with CBC encryption. This flaw allows remote attackers to trigger a denial of service (buffer over-read) or potentially other unspecified impacts through a specially crafted TLS packet. The vulnerability has a CVSS score of 6.8, indicating a medium severity, and can be exploited remotely with medium attack complexity without authentication, leading to partial confidentiality, integrity, and availability impacts. Currently, there is no known public exploit code (Metasploit, Nuclei, ExploitDB) and no evidence of active exploitation, nor has it garnered significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.9.8wCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* | ||
0.9.1cCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:0.9.1c:*:*:*:*:*:*:* | ||
0.9.2bCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:0.9.2b:*:*:*:*:*:*:* | ||
0.9.3CPE matchmatch criteria | cpe:2.3:a:openssl:openssl:0.9.3:*:*:*:*:*:*:* | ||
0.9.3aCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:0.9.3a:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.