Vulnerability Intelligence Report
CVE-2015-3195
The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1q, and 1.0.2 before 1.0.2e mishandles errors caused by malformed X509_ATTRIBUTE data, which allows remote attackers to obtain sensitive information from process memory by triggering a decoding failure in a PKCS#7 or CMS application.
No Active Exploit Signals
CVSS Base Score
5.3
MEDIUM
EPSS Probability:38.71%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| apple | mac_os_x | all |
| oracle | api_gateway | 11.1.2.3.0, 11.1.2.4.0 |
| oracle | communications_webrtc_session_controller | 7.0, 7.1, 7.2 |
| oracle | exalogic_infrastructure | 1.0, 2.0 |
| oracle | http_server | 11.5.10.2 |
| oracle | life_sciences_data_hub | 2.1 |
| oracle | sun_ray_software | 11.1 |
| oracle | transportation_management | 6.1, 6.2 |
| oracle | vm_server | 3.2 |
| oracle | vm_virtualbox | all |
| oracle | integrated_lights_out_manager_firmware | all |
| oracle | linux | 5, 6, 7 |
| oracle | solaris | 10, 11.3 |
| openssl | openssl | all |
| redhat | enterprise_linux_desktop | 5.0, 6.0, 7.0 |
| redhat | enterprise_linux_server | 5.0, 6.0, 7.0 |
| redhat | enterprise_linux_server_aus | 7.2, 7.3, 7.4, 7.6, 7.7 |
| redhat | enterprise_linux_server_tus | 7.2, 7.3, 7.6, 7.7 |
| redhat | enterprise_linux_workstation | 5.0, 6.0, 7.0 |
| canonical | ubuntu_linux | 12.04, 14.04, 15.04, 15.10 |
| debian | debian_linux | 7.0, 8.0 |
| opensuse | leap | 42.1 |
| opensuse | opensuse | 11.4, 13.1, 13.2 |
| suse | linux_enterprise_server | 10 |
| fedoraproject | fedora | 22 |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
38.709%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Red Hat, Inc. · Vendor · USA |
| Reserved | 2015-04-10T00:00:00 |
| Published | 2015-12-06T00:00:00 |
| Patch Date | 2015-12-04 |
| Last Updated | 2024-08-06T05:39:31 |
Community Chatter & Buzz