CVE Vulnerabilities

CVE-2015-1792

Published: Jun 12, 2015 | Modified: Feb 13, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

The do_free_upto function in crypto/cms/cms_smime.c in OpenSSL before 0.9.8zg, 1.0.0 before 1.0.0s, 1.0.1 before 1.0.1n, and 1.0.2 before 1.0.2b allows remote attackers to cause a denial of service (infinite loop) via vectors that trigger a NULL value of a BIO data structure, as demonstrated by an unrecognized X.660 OID for a hash function.

Affected Software

Name Vendor Start Version End Version
Openssl Openssl * 0.9.8zf
Openssl Openssl 1.0.1m 1.0.1m
Openssl Openssl 1.0.2a 1.0.2a
Openssl Openssl 1.0.1j 1.0.1j
Openssl Openssl 1.0.0n 1.0.0n
Openssl Openssl 1.0.1 1.0.1
Openssl Openssl 1.0.0c 1.0.0c
Openssl Openssl 1.0.0i 1.0.0i
Openssl Openssl 1.0.0 1.0.0
Openssl Openssl 1.0.1h 1.0.1h
Openssl Openssl 1.0.0 1.0.0
Openssl Openssl 1.0.0m 1.0.0m
Openssl Openssl 1.0.1c 1.0.1c
Openssl Openssl 1.0.1g 1.0.1g
Openssl Openssl 1.0.0h 1.0.0h
Openssl Openssl 1.0.0 1.0.0
Openssl Openssl 1.0.0e 1.0.0e
Openssl Openssl 1.0.1 1.0.1
Openssl Openssl 1.0.0f 1.0.0f
Openssl Openssl 1.0.0d 1.0.0d
Openssl Openssl 1.0.0j 1.0.0j
Openssl Openssl 1.0.0p 1.0.0p
Openssl Openssl 1.0.1a 1.0.1a
Openssl Openssl 1.0.1 1.0.1
Openssl Openssl 1.0.0o 1.0.0o
Openssl Openssl 1.0.1d 1.0.1d
Openssl Openssl 1.0.0k 1.0.0k
Openssl Openssl 1.0.0 1.0.0
Openssl Openssl 1.0.2 1.0.2
Openssl Openssl 1.0.1k 1.0.1k
Openssl Openssl 1.0.0 1.0.0
Openssl Openssl 1.0.1b 1.0.1b
Openssl Openssl 1.0.1e 1.0.1e
Openssl Openssl 1.0.0 1.0.0
Openssl Openssl 1.0.1l 1.0.1l
Openssl Openssl 1.0.1f 1.0.1f
Openssl Openssl 1.0.0l 1.0.0l
Openssl Openssl 1.0.2 1.0.2
Openssl Openssl 1.0.0r 1.0.0r
Openssl Openssl 1.0.0a 1.0.0a
Openssl Openssl 1.0.0q 1.0.0q
Openssl Openssl 1.0.1i 1.0.1i
Openssl Openssl 1.0.0b 1.0.0b
Openssl Openssl 1.0.1 1.0.1
Openssl Openssl 1.0.0g 1.0.0g

References