---
title: "CVE-2012-0884\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2012-0884?format=md
keywords: index, follow
---

# CVE-2012-0884

Publication date 12 March 2012

Last updated 24 July 2024

---

Ubuntu priority

**Low**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

The implementation of Cryptographic Message Syntax (CMS) and PKCS #7 in
OpenSSL before 0.9.8u and 1.x before 1.0.0h does not properly restrict
certain oracle behavior, which makes it easier for context-dependent
attackers to decrypt data via a Million Message Attack (MMA) adaptive
chosen ciphertext attack.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2012-0884?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| openssl | 14.04 LTS trusty | Not affected |
| 13.10 saucy | Not affected |
| 13.04 raring | Not affected |
| 12.10 quantal | Not affected |
| 12.04 LTS precise | Not affected |
| 11.10 oneiric | Fixed 1.0.0e-2ubuntu4.6 |
| 11.04 natty | Fixed 0.9.8o-5ubuntu1.7 |
| 10.10 maverick | Ignored end of life |
| 10.04 LTS lucid | Fixed 0.9.8k-7ubuntu8.13 |
| 8.04 LTS hardy | Fixed 0.9.8g-4ubuntu3.19 |
| openssl098 | 14.04 LTS trusty | Fixed 0.9.8o-7ubuntu3.2.14.04.1 |
| 13.10 saucy | Fixed 0.9.8o-7ubuntu3.2.13.10.1 |
| 13.04 raring | Ignored end of life |
| 12.10 quantal | Ignored end of life |
| 12.04 LTS precise | Fixed 0.9.8o-7ubuntu3.2 |
| 11.10 oneiric | Ignored end of life |
| 11.04 natty | Not in release |
| 10.10 maverick | Not in release |
| 10.04 LTS lucid | Not in release |
| 8.04 LTS hardy | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2012-0884?format=md#patch-details)

## Notes

---

### [sbeattie](https://launchpad.net/~sbeattie)

only affects CMS, PKCS #7, or S/MIME decryption, not SSL/TLS
transactions

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

from oss-security: "If a Linux distribution picks up the fix for
CVE-2012-0884 then they will want to pick up change 22161 at the
same time since the fix for the security vulnerability will
generally cause symmetric decryption errors when it kicks in and
things get very confusing for the end user without change 22161"
A second issue was fixed too, see:
http://www.openwall.com/lists/oss-security/2012/05/11/5

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| openssl | * Upstream:   <http://cvs.openssl.org/chngview?cn=22238> * Upstream:   <http://cvs.openssl.org/chngview?cn=22161> * Upstream:   <http://cvs.openssl.org/chngview?cn=22537> * Vendor:   <http://www.debian.org/security/2012/dsa-2454> |

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0884)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2012-0884)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2012-0884)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2012-0884)

### Related Ubuntu Security Notices (USN)

+ [USN-1451-1](https://usn.ubuntu.com/USN-1451-1)
+ OpenSSL vulnerabilities
+ 24 May 2012

### Other references

* <http://www.openssl.org/news/secadv_20120312.txt>
* <https://www.cve.org/CVERecord?id=CVE-2012-0884>
