Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/Crypt-OpenSSL-PKCS12

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

Crypt::OpenSSL::PKCS12 versions before 1.98 for Perl allow a NULL pointer dereference in print_attribute via a zero length BMPSTRING attribute. print_attribute() sizes the destination buffer for a BMPSTRING attribute from its declared byte length with `Renew(*attribute, length, char)`. A zero length attribute makes that a zero size reallocation, which Perl implements as a free returning NULL, so the buffer pointer becomes NULL, the following `strncpy` copies nothing, and the caller dereferences NULL in the `strlen()` it passes to `newSVpvn()`. A zero length BMPSTRING is even length, so the ASN.1 decoder accepts it and the value reaches this code. The UTF8STRING, OCTET STRING and BIT STRING arms size on `length + 1` or `length * 4 + 1` and are unaffected. Any caller that passes an untrusted PKCS#12 file to info_as_hash() can crash the process. info() prints attribute values directly without sizing a buffer and is unaffected.

Join the discussion

Crypt::OpenSSL::PKCS12 versions before 1.96 for Perl permits a heap OOB read in print_attribute UTF8STRING path. print_attribute() copies a UTF8STRING ASN.1 attribute value into a heap buffer sized exactly to its declared length via strncpy, leaving no NUL terminator. Downstream callers run strlen() on the result and pass the inflated length to newSVpvn(), copying attacker-influenced adjacent heap bytes into a Perl scalar.

Join the discussion

Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl improperly handle passwords containing embedded NULL bytes by truncating them at the first NULL character. This occurs because the password parameter is treated as a null-terminated C string, causing loss of entropy in binary or derived passwords without any warning. This vulnerability can lead to compromised confidentiality, integrity, and availability of cryptographic operations relying on these passwords.

Join the discussion

Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl contain a critical out-of-bounds write vulnerability triggered when parsing a specially crafted PKCS12 file with a large OCTET STRING or BIT STRING attribute. This flaw arises from a signed integer overflow during size calculation, potentially allowing remote code execution. The vulnerability has a CVSS score of 9.8, indicating critical severity. A patch is available, and since this is a cloud service, the vendor typically manages remediation server-side. No known exploits are reported in the wild at this time.

Join the discussion

Showing 1 to 4 of 4 results

Filters:Package: pkg:github/Crypt-OpenSSL-PKCS12
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses