Executive brief
A vulnerability in the Crypt::OpenSSL::PKCS12 Perl library could allow an attacker to execute malicious code or crash a system. This library is used to process PKCS#12 files, which typically contain digital certificates and private keys. By providing a specially crafted certificate file, an attacker could exploit a memory handling error to gain unauthorized access or disrupt operations.
Technical details
An integer overflow vulnerability exists in the print_attribute function within PKCS12.xs. When processing an OCTET STRING or BIT STRING attribute on a SAFEBAG, the library multiplies the attribute length by 4 to allocate a buffer. If the length is >= 1 GiB (0x40000000), the 32-bit integer multiplication overflows to 0, resulting in a near-zero byte allocation via Renew(). Subsequent data copying via get_hex() then writes approximately 3 GiB of data out-of-bounds on the heap. This can be triggered remotely if an application uses info() or info_as_hash() on untrusted PKCS12 files. The issue is fixed in version 1.95 by adding explicit length guards and promoting the calculation to size_t.
Affected products
- Perl CPAN Crypt::OpenSSL::PKCS12 through 1.94
Timeline
- 2026-05-17: disclosed
- 2026-05-17: patched: Fixed in version 1.95
- 2026-05-17: advisory
References
- https://github.com/dsully/perl-crypt-openssl-pkcs12/commit/b9d0469c6d8f5b5c6c2a45a3d0647a532b749397.patch
- https://github.com/dsully/perl-crypt-openssl-pkcs12/issues/55
- https://github.com/dsully/perl-crypt-openssl-pkcs12/issues/56
- https://metacpan.org/release/JONASBN/Crypt-OpenSSL-PKCS12-1.95/view/Changes.md