SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2015-3195

The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1q, and 1.0.2 before 1.0.2e mishandles errors caused by malformed X509_ATTRIBUTE data, which allows remote attackers to…

MEDIUM 5.3EPSS 38.7%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 38.7%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.

Description

The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1q, and 1.0.2 before 1.0.2e mishandles errors caused by malformed X509_ATTRIBUTE data, which allows remote attackers to obtain sensitive information from process memory by triggering a decoding failure in a PKCS#7 or CMS application.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
EPSS
38.71% probability · 98th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
apple/mac os x · oracle/api gateway · oracle/communications webrtc session controller · oracle/exalogic infrastructure · oracle/http server · oracle/life sciences data hub · oracle/sun ray software · oracle/transportation management · oracle/vm server · oracle/vm virtualbox · oracle/integrated lights out manager firmware · oracle/linux · oracle/solaris · openssl/openssl · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux server tus · redhat/enterprise linux workstation · canonical/ubuntu linux · +5 more
Source
secalert@redhat.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.