CVE-2015-3195
Last modified
CVE-2015-3195 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1q, and 1.0.2 before 1.0.2e mishandles errors caused by malformed X509_ATTRIBUTE data, which allows remote attackers to obtain sensitive information from process memory by triggering a decoding failure in a PKCS#7 or CMS application.. EPSS estimates a 38.71% chance of exploitation in the next 30 days.
Description
The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1q, and 1.0.2 before 1.0.2e mishandles errors caused by malformed X509_ATTRIBUTE data, which allows remote attackers to obtain sensitive information from process memory by triggering a decoding failure in a PKCS#7 or CMS application.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Apple | Mac Os X | < 10.11.4 | — |
| Oracle | Api Gateway | 11.1.2.3.0 | — |
| Oracle | Api Gateway | 11.1.2.4.0 | — |
| Oracle | Communications Webrtc Session Controller | 7.0 | — |
| Oracle | Communications Webrtc Session Controller | 7.1 | — |
| Oracle | Communications Webrtc Session Controller | 7.2 | — |
| Oracle | Exalogic Infrastructure | 1.0 | — |
| Oracle | Exalogic Infrastructure | 2.0 | — |
| Oracle | Http Server | 11.5.10.2 | — |
| Oracle | Life Sciences Data Hub | 2.1 | — |
| Oracle | Sun Ray Software | 11.1 | — |
| Oracle | Transportation Management | 6.1 | — |
| Oracle | Transportation Management | 6.2 | — |
| Oracle | Vm Server | 3.2 | — |
| Oracle | Vm Virtualbox | < 4.3.36 | — |
| Oracle | Vm Virtualbox | >= 5.0.0, < 5.0.14 | — |
| Oracle | Integrated Lights Out Manager Firmware | >= 3.0, <= 4.0.4 | — |
| Oracle | Linux | 5 | — |
| Oracle | Linux | 6 | — |
| Oracle | Linux | 7 | — |
| Oracle | Solaris | 10 | — |
| Oracle | Solaris | 11.3 | — |
| Openssl | Openssl | < 0.9.8zh | — |
| Openssl | Openssl | >= 1.0.0, < 1.0.0t | — |
| Openssl | Openssl | >= 1.0.1, < 1.0.1q | — |
| Openssl | Openssl | >= 1.0.2, < 1.0.2e | — |
| Redhat | Enterprise Linux Desktop | 5.0 | — |
| Redhat | Enterprise Linux Desktop | 6.0 | — |
| Redhat | Enterprise Linux Desktop | 7.0 | — |
| Redhat | Enterprise Linux Server | 5.0 | — |
| Redhat | Enterprise Linux Server | 6.0 | — |
| Redhat | Enterprise Linux Server | 7.0 | — |
| Redhat | Enterprise Linux Server Aus | 7.2 | — |
| Redhat | Enterprise Linux Server Aus | 7.3 | — |
| Redhat | Enterprise Linux Server Aus | 7.4 | — |
| Redhat | Enterprise Linux Server Aus | 7.6 | — |
| Redhat | Enterprise Linux Server Aus | 7.7 | — |
| Redhat | Enterprise Linux Server Tus | 7.2 | — |
| Redhat | Enterprise Linux Server Tus | 7.3 | — |
| Redhat | Enterprise Linux Server Tus | 7.6 | — |
| Redhat | Enterprise Linux Server Tus | 7.7 | — |
| Redhat | Enterprise Linux Workstation | 5.0 | — |
| Redhat | Enterprise Linux Workstation | 6.0 | — |
| Redhat | Enterprise Linux Workstation | 7.0 | — |
| Canonical | Ubuntu Linux | 12.04 | — |
| Canonical | Ubuntu Linux | 14.04 | — |
| Canonical | Ubuntu Linux | 15.04 | — |
| Canonical | Ubuntu Linux | 15.10 | — |
| Debian | Debian Linux | 7.0 | — |
| Debian | Debian Linux | 8.0 | — |
Showing 50 of 56 affected configurations. See NVD for the full list.
References
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10733Third Party Advisory
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10759Third Party Advisory
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761Third Party Advisory
- http://lists.apple.com/archives/security-announce/2016/Mar/msg00004.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00009.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00017.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2015-12/msg00070.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2015-12/msg00071.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2015-12/msg00087.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2015-12/msg00103.htmlMailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=145382583417444&w=2Mailing List, Third Party Advisory
- http://openssl.org/news/secadv/20151203.txtVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2015-2616.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-2617.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-2957.htmlThird Party Advisory
- http://www.debian.org/security/2015/dsa-3413Third Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.htmlThird Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlThird Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.htmlThird Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.htmlThird Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.htmlThird Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.htmlThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.htmlThird Party Advisory
- http://www.securityfocus.com/bid/78626Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/91787Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1034294Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2830-1Third Party Advisory
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA40100Third Party Advisory
- https://support.apple.com/HT206167Third Party Advisory
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10733Third Party Advisory
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10759Third Party Advisory
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761Third Party Advisory
- http://lists.apple.com/archives/security-announce/2016/Mar/msg00004.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00009.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00017.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2015-12/msg00070.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2015-12/msg00071.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2015-12/msg00087.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2015-12/msg00103.htmlMailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=145382583417444&w=2Mailing List, Third Party Advisory
- http://openssl.org/news/secadv/20151203.txtVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2015-2616.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-2617.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-2957.htmlThird Party Advisory
- http://www.debian.org/security/2015/dsa-3413Third Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.htmlThird Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlThird Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.htmlThird Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.htmlThird Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.htmlThird Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.htmlThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.htmlThird Party Advisory
- http://www.securityfocus.com/bid/78626Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/91787Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1034294Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2830-1Third Party Advisory
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA40100Third Party Advisory
- https://support.apple.com/HT206167Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-3195?
How severe is CVE-2015-3195?
How do I fix CVE-2015-3195?
Are you affected by CVE-2015-3195?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
