Double-free in Policy Checks (CVE-2011-4109) ============================================ If X509_V_FLAG_POLICY_CHECK is set in OpenSSL 0.9.8, then a policy check failure can lead to a double-free. The bug does not occur unless this flag is set. Users of OpenSSL 1.0.0 are not affected. This flaw was discovered by Ben Laurie and a fix provided by Emilia Kasper <ekasper> of Google. Affected users should upgrade to OpenSSL 0.9.8s. Reference: http://openssl.org/news/secadv_20120104.txt
Seems to be the fix here: http://cvs.openssl.org/chngview?cn=21941
Created mingw32-openssl tracking bugs for this issue Affects: epel-5 [bug 773331]
This issue has been addressed in following products: Red Hat Enterprise Linux 5 Via RHSA-2012:0060 https://rhn.redhat.com/errata/RHSA-2012-0060.html
The affected functions are not present in openssl 0.9.7a either, so Red Hat Enterprise Linux 4 is not affected by this flaw either. Statement: This issue did not affect the versions of openssl as shipped with Red Hat Enterprise Linux 4 and 6.
This issue has been addressed in following products: RHEV-H, V2V and Agents for RHEL-5 Via RHSA-2012:0168 https://rhn.redhat.com/errata/RHSA-2012-0168.html
This issue has been addressed in following products: JBoss Enterprise Application Platform 6.0.0 Via RHSA-2012:1308 https://rhn.redhat.com/errata/RHSA-2012-1308.html
This issue has been addressed in following products: JBoss Enterprise Application Platform 5.1.2 Via RHSA-2012:1307 https://rhn.redhat.com/errata/RHSA-2012-1307.html
This issue has been addressed in following products: JBoss Enterprise Web Server 1.0.2 Via RHSA-2012:1306 https://rhn.redhat.com/errata/RHSA-2012-1306.html