Severity
6.8MEDIUMNVD
EPSS
2.5%
top 14.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 19
Latest updateNov 7

Description

Use-after-free vulnerability in the d2i_ECPrivateKey function in crypto/ec/ec_asn1.c in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a might allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a malformed Elliptic Curve (EC) private-key file that is improperly handled during import.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages7 packages

debiandebian/openssl< openssl 1.0.1k-2 (bookworm)
Debianopenssl/openssl< 1.0.1k-2+3
Ubuntuopenssl/openssl< 1.0.1f-1ubuntu2.11
NVDopenssl/openssl0.9.8ze+32

🔴Vulnerability Details

3
GHSA
GHSA-gc3c-j46x-fm67: Use-after-free vulnerability in the d2i_ECPrivateKey function in crypto/ec/ec_asn12022-05-14
OSV
CVE-2015-0209: Use-after-free vulnerability in the d2i_ECPrivateKey function in crypto/ec/ec_asn12015-03-19
OSV
openssl vulnerabilities2015-03-19

📋Vendor Advisories

22
Palo Alto
PAN-SA-2024-0014 Informational Bulletin: Impact of OSS CVEs in Cortex XDR Agent2024-11-07
CISA ICS
Siemens SCALANCE X-200RNA Switch Devices2022-12-19
CISA ICS
Rockwell Automation Stratix 59002017-05-10
Cisco
Multiple Vulnerabilities in OpenSSL (March 2015) Affecting Cisco Products2015-03-20
BSD
FreeBSD-SA-15:06.openssl: Multiple OpenSSL vulnerabilities2015-03-19

🕵️Threat Intelligence

2
Tenable
[R3] LCE 5.0.0 Fixes Multiple Third-party Library Vulnerabilities2017-01-31
Tenable
[R6] OpenSSL &#039;20150319&#039; Advisory Affects Tenable Products2015-03-29

💬Community

4
Bugzilla
CVE-2015-0209 CVE-2015-0293 CVE-2015-0287 CVE-2015-0286 CVE-2015-0289 CVE-2015-0288 mingw-openssl: various flaws [epel-7]2015-03-19
Bugzilla
CVE-2015-0209 CVE-2015-0293 CVE-2015-0287 CVE-2015-0286 CVE-2015-0289 CVE-2015-0288 mingw-openssl: various flaws [fedora-all]2015-03-19
Bugzilla
CVE-2015-0292 CVE-2015-0209 CVE-2015-0287 CVE-2015-0286 CVE-2015-0289 CVE-2015-0288 openssl: various flaws [fedora-all]2015-02-26
Bugzilla
CVE-2015-0209 openssl: use-after-free on invalid EC private key import2015-02-26
CVE-2015-0209 — Use After Free in Debian Openssl | cvebase