CVE-2015-0205Improper Input Validation in Openssl

Severity
5.0MEDIUMNVD
EPSS
12.3%
top 6.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 9
Latest updateMay 17

Description

The ssl3_get_cert_verify function in s3_srvr.c in OpenSSL 1.0.0 before 1.0.0p and 1.0.1 before 1.0.1k accepts client authentication with a Diffie-Hellman (DH) certificate without requiring a CertificateVerify message, which allows remote attackers to obtain access without knowledge of a private key via crafted TLS Handshake Protocol traffic to a server that recognizes a Certification Authority with DH support.

CVSS vector

AV:N/AC:L/C:N/I:P/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages5 packages

debiandebian/openssl< openssl 1.0.1k-1 (bookworm)
Debianopenssl/openssl< 1.0.1k-1+3
Ubuntuopenssl/openssl< 1.0.1f-1ubuntu2.8
NVDopenssl/openssl25 versions+24

🔴Vulnerability Details

3
GHSA
GHSA-j635-3m2r-m6v7: The ssl3_get_cert_verify function in s3_srvr2022-05-17
OSV
openssl vulnerabilities2015-01-12
OSV
CVE-2015-0205: The ssl3_get_cert_verify function in s3_srvr2015-01-09

📋Vendor Advisories

13
Cisco
Multiple Vulnerabilities in OpenSSL (January 2015) Affecting Cisco Products2015-03-10
BSD
FreeBSD-SA-15:01.openssl: OpenSSL multiple vulnerabilities2015-01-14
Ubuntu
OpenSSL vulnerabilities2015-01-12
Red Hat
openssl: DH client certificates accepted without verification2015-01-08
Debian
CVE-2015-0205: openssl - The ssl3_get_cert_verify function in s3_srvr.c in OpenSSL 1.0.0 before 1.0.0p an...2015

🕵️Threat Intelligence

1
Tenable
[R3] LCE 5.0.0 Fixes Multiple Third-party Library Vulnerabilities2017-01-31

📄Research Papers

1
arXiv
Server-side verification of client behavior in cryptographic protocols2016-03-13

💬Community

2
Bugzilla
CVE-2014-3570 CVE-2014-3571 CVE-2015-0205 CVE-2015-0206 openssl: various flaws [fedora-all]2015-01-12
Bugzilla
CVE-2015-0205 openssl: DH client certificates accepted without verification2015-01-08