CVE-2015-3195
06.12.2015, 20:59
The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1q, and 1.0.2 before 1.0.2e mishandles errors caused by malformed X509_ATTRIBUTE data, which allows remote attackers to obtain sensitive information from process memory by triggering a decoding failure in a PKCS#7 or CMS application.Enginsight
| Vendor | Product | Version |
|---|---|---|
| apple | mac_os_x | 𝑥 < 10.11.4 |
| oracle | api_gateway | 11.1.2.3.0 |
| oracle | api_gateway | 11.1.2.4.0 |
| oracle | communications_webrtc_session_controller | 7.0 |
| oracle | communications_webrtc_session_controller | 7.1 |
| oracle | communications_webrtc_session_controller | 7.2 |
| oracle | exalogic_infrastructure | 1.0 |
| oracle | exalogic_infrastructure | 2.0 |
| oracle | http_server | 11.5.10.2 |
| oracle | life_sciences_data_hub | 2.1 |
| oracle | sun_ray_software | 11.1 |
| oracle | transportation_management | 6.1 |
| oracle | transportation_management | 6.2 |
| oracle | vm_server | 3.2 |
| oracle | vm_virtualbox | 𝑥 < 4.3.36 |
| oracle | vm_virtualbox | 5.0.0 ≤ 𝑥 < 5.0.14 |
| oracle | integrated_lights_out_manager_firmware | 3.0 ≤ 𝑥 ≤ 4.0.4 |
| oracle | solaris | 11.3 |
| openssl | openssl | 𝑥 < 0.9.8zh |
| openssl | openssl | 1.0.0 ≤ 𝑥 < 1.0.0t |
| openssl | openssl | 1.0.1 ≤ 𝑥 < 1.0.1q |
| openssl | openssl | 1.0.2 ≤ 𝑥 < 1.0.2e |
| redhat | enterprise_linux_desktop | 5.0 |
| redhat | enterprise_linux_desktop | 6.0 |
| redhat | enterprise_linux_desktop | 7.0 |
| redhat | enterprise_linux_server | 5.0 |
| redhat | enterprise_linux_server | 6.0 |
| redhat | enterprise_linux_server | 7.0 |
| redhat | enterprise_linux_server_aus | 7.2 |
| redhat | enterprise_linux_server_aus | 7.3 |
| redhat | enterprise_linux_server_aus | 7.4 |
| redhat | enterprise_linux_server_aus | 7.6 |
| redhat | enterprise_linux_server_aus | 7.7 |
| redhat | enterprise_linux_server_tus | 7.2 |
| redhat | enterprise_linux_server_tus | 7.3 |
| redhat | enterprise_linux_server_tus | 7.6 |
| redhat | enterprise_linux_server_tus | 7.7 |
| redhat | enterprise_linux_workstation | 5.0 |
| redhat | enterprise_linux_workstation | 6.0 |
| redhat | enterprise_linux_workstation | 7.0 |
| canonical | ubuntu_linux | 12.04 |
| canonical | ubuntu_linux | 14.04 |
| canonical | ubuntu_linux | 15.04 |
| canonical | ubuntu_linux | 15.10 |
| debian | debian_linux | 7.0 |
| debian | debian_linux | 8.0 |
| opensuse | leap | 42.1 |
| opensuse | opensuse | 11.4 |
| opensuse | opensuse | 13.1 |
| opensuse | opensuse | 13.2 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| openssl |
| ||||||||||||||||||||||
| openssl098 |
|
Common Weakness Enumeration