Source: libcrypt-openssl-pkcs12-perl Version: 1.97-1 Severity: important Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for libcrypt-openssl-pkcs12-perl. CVE-2026-17510[0]: | Crypt::OpenSSL::PKCS12 versions before 1.98 for Perl allow a NULL | pointer dereference in print_attribute via a zero length BMPSTRING | attribute. print_attribute() sizes the destination buffer for a | BMPSTRING attribute from its declared byte length with | `Renew(*attribute, length, char)`. A zero length attribute makes | that a zero size reallocation, which Perl implements as a free | returning NULL, so the buffer pointer becomes NULL, the following | `strncpy` copies nothing, and the caller dereferences NULL in the | `strlen()` it passes to `newSVpvn()`. A zero length BMPSTRING is | even length, so the ASN.1 decoder accepts it and the value reaches | this code. The UTF8STRING, OCTET STRING and BIT STRING arms size on | `length + 1` or `length * 4 + 1` and are unaffected. Any caller | that passes an untrusted PKCS#12 file to info_as_hash() can crash | the process. info() prints attribute values directly without sizing | a buffer and is unaffected. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-17510 https://www.cve.org/CVERecord?id=CVE-2026-17510 [1] https://lists.security.metacpan.org/cve-announce/msg/42524422/ Regards, Salvatore

