Skip to content

[GHSA-wwwj-58hm-mxm3] The implementation of Cryptographic Message Syntax (CMS)...#7363

Open
tjuyuxinzhang wants to merge 1 commit intotjuyuxinzhang/advisory-improvement-7363from
tjuyuxinzhang-GHSA-wwwj-58hm-mxm3
Open

[GHSA-wwwj-58hm-mxm3] The implementation of Cryptographic Message Syntax (CMS)...#7363
tjuyuxinzhang wants to merge 1 commit intotjuyuxinzhang/advisory-improvement-7363from
tjuyuxinzhang-GHSA-wwwj-58hm-mxm3

Conversation

@tjuyuxinzhang
Copy link
Copy Markdown

Updates

  • Affected products
  • References
  • Source code location
  • Summary

Comments
The current advisory is incomplete and lacks a precise technical description, stable references, and weakness classification. This update improves the title and description to reflect that CVE-2012-0884 is an OpenSSL CMS/PKCS#7 oracle-behavior issue enabling a Million Message Attack (MMA) adaptive chosen-ciphertext attack, adds authoritative references, and aligns the weakness field with existing source reports that classify the issue as CWE-310.

@github-actions github-actions bot changed the base branch from main to tjuyuxinzhang/advisory-improvement-7363 April 11, 2026 15:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant