← Back to CVE List
Vulnerability Intelligence Report

CVE-2015-3195

The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1q, and 1.0.2 before 1.0.2e mishandles errors caused by malformed X509_ATTRIBUTE data, which allows remote attackers to obtain sensitive information from process memory by triggering a decoding failure in a PKCS#7 or CMS application.

No Active Exploit Signals
CVSS Base Score
5.3
MEDIUM
EPSS Probability:38.71%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
apple mac_os_x all
oracle api_gateway 11.1.2.3.0, 11.1.2.4.0
oracle communications_webrtc_session_controller 7.0, 7.1, 7.2
oracle exalogic_infrastructure 1.0, 2.0
oracle http_server 11.5.10.2
oracle life_sciences_data_hub 2.1
oracle sun_ray_software 11.1
oracle transportation_management 6.1, 6.2
oracle vm_server 3.2
oracle vm_virtualbox all
oracle integrated_lights_out_manager_firmware all
oracle linux 5, 6, 7
oracle solaris 10, 11.3
openssl openssl all
redhat enterprise_linux_desktop 5.0, 6.0, 7.0
redhat enterprise_linux_server 5.0, 6.0, 7.0
redhat enterprise_linux_server_aus 7.2, 7.3, 7.4, 7.6, 7.7
redhat enterprise_linux_server_tus 7.2, 7.3, 7.6, 7.7
redhat enterprise_linux_workstation 5.0, 6.0, 7.0
canonical ubuntu_linux 12.04, 14.04, 15.04, 15.10
debian debian_linux 7.0, 8.0
opensuse leap 42.1
opensuse opensuse 11.4, 13.1, 13.2
suse linux_enterprise_server 10
fedoraproject fedora 22

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
38.709%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityRed Hat, Inc. · Vendor · USA
Reserved2015-04-10T00:00:00
Published2015-12-06T00:00:00
Patch Date2015-12-04
Last Updated2024-08-06T05:39:31

LINK COPIED TO CLIPBOARD