The OpenSSL developers have had to re-release the fix for a serious vulnerability in the software s ASN.1 implementation that could allow an attacker to cause a denial of service or potentially run arbitrary code on a remote machine. The updated fix only applies to version 0.9.8v; all of the other previously affected versions are already protected with the existing patch. The original advisory and fix for the CVE-2012-2110 vulnerability was released last week, but after releasing the fixes, Red Hat discovered that the fix didn t completely address the vulnerability.
Source: https://threatpost.com/openssl-releases-new-fix-cve-2012-2110-asn1-bug-042412/76477/

