CVE Vulnerabilities

CVE-2015-0287

Published: Mar 19, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
2.6 LOW
AV:N/AC:H/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The ASN1_item_ex_d2i function in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a does not reinitialize CHOICE and ADB data structures, which might allow attackers to cause a denial of service (invalid write operation and memory corruption) by leveraging an application that relies on ASN.1 structure reuse.

Affected Software

NameVendorStart VersionEnd Version
OpensslOpenssl*0.9.8ze (including)
OpensslOpenssl1.0.0 (including)1.0.0 (including)
OpensslOpenssl1.0.0a (including)1.0.0a (including)
OpensslOpenssl1.0.0b (including)1.0.0b (including)
OpensslOpenssl1.0.0c (including)1.0.0c (including)
OpensslOpenssl1.0.0d (including)1.0.0d (including)
OpensslOpenssl1.0.0e (including)1.0.0e (including)
OpensslOpenssl1.0.0f (including)1.0.0f (including)
OpensslOpenssl1.0.0g (including)1.0.0g (including)
OpensslOpenssl1.0.0h (including)1.0.0h (including)
OpensslOpenssl1.0.0i (including)1.0.0i (including)
OpensslOpenssl1.0.0j (including)1.0.0j (including)
OpensslOpenssl1.0.0k (including)1.0.0k (including)
OpensslOpenssl1.0.0l (including)1.0.0l (including)
OpensslOpenssl1.0.0m (including)1.0.0m (including)
OpensslOpenssl1.0.0n (including)1.0.0n (including)
OpensslOpenssl1.0.0o (including)1.0.0o (including)
OpensslOpenssl1.0.0p (including)1.0.0p (including)
OpensslOpenssl1.0.0q (including)1.0.0q (including)
OpensslOpenssl1.0.1 (including)1.0.1 (including)
OpensslOpenssl1.0.1a (including)1.0.1a (including)
OpensslOpenssl1.0.1b (including)1.0.1b (including)
OpensslOpenssl1.0.1c (including)1.0.1c (including)
OpensslOpenssl1.0.1d (including)1.0.1d (including)
OpensslOpenssl1.0.1e (including)1.0.1e (including)
OpensslOpenssl1.0.1f (including)1.0.1f (including)
OpensslOpenssl1.0.1g (including)1.0.1g (including)
OpensslOpenssl1.0.1h (including)1.0.1h (including)
OpensslOpenssl1.0.1i (including)1.0.1i (including)
OpensslOpenssl1.0.1j (including)1.0.1j (including)
OpensslOpenssl1.0.1k (including)1.0.1k (including)
OpensslOpenssl1.0.1l (including)1.0.1l (including)
OpensslOpenssl1.0.2 (including)1.0.2 (including)
Red Hat Enterprise Linux 5RedHatopenssl-0:0.9.8e-33.el5_11*
Red Hat Enterprise Linux 6RedHatopenssl-0:1.0.1e-30.el6_6.7*
Red Hat Enterprise Linux 7RedHatopenssl-1:1.0.1e-42.el7_1.4*
Red Hat Storage 2.1RedHatopenssl-0:1.0.1e-30.el6_6.7*
OpensslUbuntuartful*
OpensslUbuntubionic*
OpensslUbuntucosmic*
OpensslUbuntudevel*
OpensslUbuntudisco*
OpensslUbuntuesm-infra-legacy/trusty*
OpensslUbuntuesm-infra/bionic*
OpensslUbuntuesm-infra/xenial*
OpensslUbuntulucid*
OpensslUbuntuprecise*
OpensslUbuntutrusty*
OpensslUbuntutrusty/esm*
OpensslUbuntuutopic*
OpensslUbuntuvivid*
OpensslUbuntuvivid/stable-phone-overlay*
OpensslUbuntuvivid/ubuntu-core*
OpensslUbuntuwily*
OpensslUbuntuxenial*
OpensslUbuntuyakkety*
OpensslUbuntuzesty*
Openssl098Ubuntuprecise*
Openssl098Ubuntutrusty*
Openssl098Ubuntuutopic*
Openssl098Ubuntuvivid*

References