CVE Vulnerabilities

CVE-2015-1792

Published: Jun 12, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The do_free_upto function in crypto/cms/cms_smime.c in OpenSSL before 0.9.8zg, 1.0.0 before 1.0.0s, 1.0.1 before 1.0.1n, and 1.0.2 before 1.0.2b allows remote attackers to cause a denial of service (infinite loop) via vectors that trigger a NULL value of a BIO data structure, as demonstrated by an unrecognized X.660 OID for a hash function.

Affected Software

NameVendorStart VersionEnd Version
OpensslOpenssl*0.9.8zf (including)
OpensslOpenssl1.0.0 (including)1.0.0 (including)
OpensslOpenssl1.0.0-beta1 (including)1.0.0-beta1 (including)
OpensslOpenssl1.0.0-beta2 (including)1.0.0-beta2 (including)
OpensslOpenssl1.0.0-beta3 (including)1.0.0-beta3 (including)
OpensslOpenssl1.0.0-beta4 (including)1.0.0-beta4 (including)
OpensslOpenssl1.0.0-beta5 (including)1.0.0-beta5 (including)
OpensslOpenssl1.0.0a (including)1.0.0a (including)
OpensslOpenssl1.0.0b (including)1.0.0b (including)
OpensslOpenssl1.0.0c (including)1.0.0c (including)
OpensslOpenssl1.0.0d (including)1.0.0d (including)
OpensslOpenssl1.0.0e (including)1.0.0e (including)
OpensslOpenssl1.0.0f (including)1.0.0f (including)
OpensslOpenssl1.0.0g (including)1.0.0g (including)
OpensslOpenssl1.0.0h (including)1.0.0h (including)
OpensslOpenssl1.0.0i (including)1.0.0i (including)
OpensslOpenssl1.0.0j (including)1.0.0j (including)
OpensslOpenssl1.0.0k (including)1.0.0k (including)
OpensslOpenssl1.0.0l (including)1.0.0l (including)
OpensslOpenssl1.0.0m (including)1.0.0m (including)
OpensslOpenssl1.0.0n (including)1.0.0n (including)
OpensslOpenssl1.0.0o (including)1.0.0o (including)
OpensslOpenssl1.0.0p (including)1.0.0p (including)
OpensslOpenssl1.0.0q (including)1.0.0q (including)
OpensslOpenssl1.0.0r (including)1.0.0r (including)
OpensslOpenssl1.0.1 (including)1.0.1 (including)
OpensslOpenssl1.0.1-beta1 (including)1.0.1-beta1 (including)
OpensslOpenssl1.0.1-beta2 (including)1.0.1-beta2 (including)
OpensslOpenssl1.0.1-beta3 (including)1.0.1-beta3 (including)
OpensslOpenssl1.0.1a (including)1.0.1a (including)
OpensslOpenssl1.0.1b (including)1.0.1b (including)
OpensslOpenssl1.0.1c (including)1.0.1c (including)
OpensslOpenssl1.0.1d (including)1.0.1d (including)
OpensslOpenssl1.0.1e (including)1.0.1e (including)
OpensslOpenssl1.0.1f (including)1.0.1f (including)
OpensslOpenssl1.0.1g (including)1.0.1g (including)
OpensslOpenssl1.0.1h (including)1.0.1h (including)
OpensslOpenssl1.0.1i (including)1.0.1i (including)
OpensslOpenssl1.0.1j (including)1.0.1j (including)
OpensslOpenssl1.0.1k (including)1.0.1k (including)
OpensslOpenssl1.0.1l (including)1.0.1l (including)
OpensslOpenssl1.0.1m (including)1.0.1m (including)
OpensslOpenssl1.0.2 (including)1.0.2 (including)
OpensslOpenssl1.0.2-beta1 (including)1.0.2-beta1 (including)
OpensslOpenssl1.0.2a (including)1.0.2a (including)
Red Hat Enterprise Linux 6RedHatopenssl-0:1.0.1e-30.el6_6.11*
Red Hat Enterprise Linux 7RedHatopenssl-1:1.0.1e-42.ael7b_1.8*
OpensslUbuntuartful*
OpensslUbuntubionic*
OpensslUbuntucosmic*
OpensslUbuntudevel*
OpensslUbuntudisco*
OpensslUbuntuesm-infra-legacy/trusty*
OpensslUbuntuesm-infra/bionic*
OpensslUbuntuesm-infra/xenial*
OpensslUbuntuprecise*
OpensslUbuntutrusty*
OpensslUbuntutrusty/esm*
OpensslUbuntuutopic*
OpensslUbuntuvivid*
OpensslUbuntuvivid/stable-phone-overlay*
OpensslUbuntuvivid/ubuntu-core*
OpensslUbuntuwily*
OpensslUbuntuxenial*
OpensslUbuntuyakkety*
OpensslUbuntuzesty*
Openssl098Ubuntuprecise*
Openssl098Ubuntutrusty*
Openssl098Ubuntuutopic*
Openssl098Ubuntuvivid*

References