CVE-2015-3195
The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1q, and 1.0.2 before 1.0.2e mishandles errors caused by malformed X509_ATTRIBUTE data, which allows remote attackers to…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 38.7%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1q, and 1.0.2 before 1.0.2e mishandles errors caused by malformed X509_ATTRIBUTE data, which allows remote attackers to obtain sensitive information from process memory by triggering a decoding failure in a PKCS#7 or CMS application.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- EPSS
- 38.71% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- apple/mac os x · oracle/api gateway · oracle/communications webrtc session controller · oracle/exalogic infrastructure · oracle/http server · oracle/life sciences data hub · oracle/sun ray software · oracle/transportation management · oracle/vm server · oracle/vm virtualbox · oracle/integrated lights out manager firmware · oracle/linux · oracle/solaris · openssl/openssl · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux server tus · redhat/enterprise linux workstation · canonical/ubuntu linux · +5 more
- Source
- secalert@redhat.com
References
- http://fortiguard.com/advisory/openssl-advisory-december-2015Broken Link
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10733Third Party Advisory
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10759Third Party Advisory
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761Third Party Advisory
- http://lists.apple.com/archives/security-announce/2016/Mar/msg00004.htmlMailing List, Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2015-December/173801.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00009.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00017.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2015-12/msg00070.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2015-12/msg00071.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2015-12/msg00087.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2015-12/msg00103.htmlMailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=145382583417444&w=2Mailing List, Third Party Advisory
- http://openssl.org/news/secadv/20151203.txtVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2015-2616.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-2617.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-2056.htmlBroken Link
- http://rhn.redhat.com/errata/RHSA-2016-2957.htmlThird Party Advisory
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151204-opensslThird Party Advisory
- http://www.debian.org/security/2015/dsa-3413Third Party Advisory
- http://www.fortiguard.com/advisory/openssl-advisory-december-2015Broken Link
- http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.htmlThird Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlThird Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.htmlThird Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.htmlThird Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.htmlThird Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.htmlThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.htmlThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.