CVE-2015-3195
06.12.2015, 20:59
The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1q, and 1.0.2 before 1.0.2e mishandles errors caused by malformed X509_ATTRIBUTE data, which allows remote attackers to obtain sensitive information from process memory by triggering a decoding failure in a PKCS#7 or CMS application.Enginsight
Vendor | Product | Version |
---|---|---|
apple | mac_os_x | 𝑥 < 10.11.4 |
oracle | api_gateway | 11.1.2.3.0 |
oracle | api_gateway | 11.1.2.4.0 |
oracle | communications_webrtc_session_controller | 7.0 |
oracle | communications_webrtc_session_controller | 7.1 |
oracle | communications_webrtc_session_controller | 7.2 |
oracle | exalogic_infrastructure | 1.0 |
oracle | exalogic_infrastructure | 2.0 |
oracle | http_server | 11.5.10.2 |
oracle | life_sciences_data_hub | 2.1 |
oracle | sun_ray_software | 11.1 |
oracle | transportation_management | 6.1 |
oracle | transportation_management | 6.2 |
oracle | vm_server | 3.2 |
oracle | vm_virtualbox | 𝑥 < 4.3.36 |
oracle | vm_virtualbox | 5.0.0 ≤ 𝑥 < 5.0.14 |
oracle | integrated_lights_out_manager_firmware | 3.0 ≤ 𝑥 ≤ 4.0.4 |
oracle | solaris | 11.3 |
openssl | openssl | 𝑥 < 0.9.8zh |
openssl | openssl | 1.0.0 ≤ 𝑥 < 1.0.0t |
openssl | openssl | 1.0.1 ≤ 𝑥 < 1.0.1q |
openssl | openssl | 1.0.2 ≤ 𝑥 < 1.0.2e |
redhat | enterprise_linux_desktop | 5.0 |
redhat | enterprise_linux_desktop | 6.0 |
redhat | enterprise_linux_desktop | 7.0 |
redhat | enterprise_linux_server | 5.0 |
redhat | enterprise_linux_server | 6.0 |
redhat | enterprise_linux_server | 7.0 |
redhat | enterprise_linux_server_aus | 7.2 |
redhat | enterprise_linux_server_aus | 7.3 |
redhat | enterprise_linux_server_aus | 7.4 |
redhat | enterprise_linux_server_aus | 7.6 |
redhat | enterprise_linux_server_aus | 7.7 |
redhat | enterprise_linux_server_tus | 7.2 |
redhat | enterprise_linux_server_tus | 7.3 |
redhat | enterprise_linux_server_tus | 7.6 |
redhat | enterprise_linux_server_tus | 7.7 |
redhat | enterprise_linux_workstation | 5.0 |
redhat | enterprise_linux_workstation | 6.0 |
redhat | enterprise_linux_workstation | 7.0 |
canonical | ubuntu_linux | 12.04 |
canonical | ubuntu_linux | 14.04 |
canonical | ubuntu_linux | 15.04 |
canonical | ubuntu_linux | 15.10 |
debian | debian_linux | 7.0 |
debian | debian_linux | 8.0 |
opensuse | leap | 42.1 |
opensuse | opensuse | 11.4 |
opensuse | opensuse | 13.1 |
opensuse | opensuse | 13.2 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
openssl |
| ||||||||||||||||||||||
openssl098 |
|
Common Weakness Enumeration