V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2015-1792
DEB
MediumConfirmedExploit available

The do_free_upto function in crypto/cms/cms_smime.c in OpenSSL before 0.9.8zg, 1.0.0 before 1.0.0s, 1.0.1 before 1.0.1n, and 1.0.2 before 1…

CVSS
4.3
Medium
EPSS
0.22
p97
Published
2015-01-01
Updated
2015-01-01
Description

The do_free_upto function in crypto/cms/cms_smime.c in OpenSSL before 0.9.8zg, 1.0.0 before 1.0.0s, 1.0.1 before 1.0.1n, and 1.0.2 before 1.0.2b allows remote attackers to cause a denial of service (infinite loop) via vectors that trigger a NULL value of a BIO data structure, as demonstrated by an unrecognized X.660 OID for a hash function.

Tags · CWE
CWE-399
CWE-835
Affected products
Openssl ≤ 0.9.8zfOpenssl
CVSS vector
AV:N/AC:M/Au:N/C:N/I:N/A:P
Timeline
2015-01-01
Published
2015-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: M
Medium
Authentication
Au: N
None (N)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: N
None (N)
Availability Impact
A: P
Partial
Exploit indicators
EPSS
0.225 · p97
Known exploited (KEV)
No
Known exploits — Сканер-ВС
CVE-2015-1792
github-poc · https://github.com/Trinadh465/OpenSSL-1_0_1g_CVE-2015-1792
Enterprise
Affected products
ProductVendorStatus
opensslTracked
opensslTracked
opensslTracked
opensslTracked
opensslTracked
opensslTracked
opensslTracked
opensslTracked
opensslTracked
opensslTracked
opensslTracked
opensslTracked
opensslTracked
opensslTracked
openssl098Tracked
openssl098Tracked
openssl098Tracked
openssl*Tracked
Source databases
DEB
CVE
RED
UBU
Related vulnerabilities