CVE-2015-0287
published 2015-03-19CVE-2015-0287: The ASN1_item_ex_d2i function in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a does not…
PriorityP430medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
8.37%
94.3th percentile
The ASN1_item_ex_d2i function in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a does not reinitialize CHOICE and ADB data structures, which might allow attackers to cause a denial of service (invalid write operation and memory corruption) by leveraging an application that relies on ASN.1 structure reuse.
Affected
43 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_9 | — | — |
| apple | os_x_el_capitan_v10.11 | — | — |
| apple | os_x_yosemite_v10.10.4_and_security_update_2015-005 | — | — |
| cisco | products | — | — |
| debian | openssl | < openssl 1.0.1k-2 (bookworm) | openssl 1.0.1k-2 (bookworm) |
| openssl | openssl | <= 0.9.8ze | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv6.8MEDIUM
vendor_ubuntu6.8MEDIUM
vendor_cisco5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7mxg-8jv7-cj7v: The ASN1_item_ex_d2i function in crypto/asn1/tasn_dec
ghsa_unreviewed·2022-05-17
CVE-2015-0287 [MEDIUM] GHSA-7mxg-8jv7-cj7v: The ASN1_item_ex_d2i function in crypto/asn1/tasn_dec
The ASN1_item_ex_d2i function in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a does not reinitialize CHOICE and ADB data structures, which might allow attackers to cause a denial of service (invalid write operation and memory corruption) by leveraging an application that relies on ASN.1 structure reuse.
OSV
CVE-2015-0287: The ASN1_item_ex_d2i function in crypto/asn1/tasn_dec
osv·2015-03-19·CVSS 5.0
CVE-2015-0287 [MEDIUM] CVE-2015-0287: The ASN1_item_ex_d2i function in crypto/asn1/tasn_dec
The ASN1_item_ex_d2i function in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a does not reinitialize CHOICE and ADB data structures, which might allow attackers to cause a denial of service (invalid write operation and memory corruption) by leveraging an application that relies on ASN.1 structure reuse.
OSV
openssl vulnerabilities
osv·2015-03-19·CVSS 6.8
CVE-2015-0209 [MEDIUM] openssl vulnerabilities
openssl vulnerabilities
It was discovered that OpenSSL incorrectly handled malformed EC private key
files. A remote attacker could possibly use this issue to cause OpenSSL to
crash, resulting in a denial of service, or execute arbitrary code.
(CVE-2015-0209)
Stephen Henson discovered that OpenSSL incorrectly handled comparing ASN.1
boolean types. A remote attacker could possibly use this issue to cause
OpenSSL to crash, resulting in a denial of service. (CVE-2015-0286)
Emilia Käsper discovered that OpenSSL incorrectly handled ASN.1 structure
reuse. A remote attacker could possibly use this issue to cause OpenSSL to
crash, resulting in a denial of service, or execute arbitrary code.
(CVE-2015-0287)
Brian Carpenter discovered that OpenSSL incorrectly handled invalid
certificate keys. A r
CISA ICS
Siemens SCALANCE X-200RNA Switch Devices
cisa_ics·2022-12-19
Siemens SCALANCE X-200RNA Switch Devices
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SCALANCE X-200RNA Switch Devices
Last RevisedDecember 19, 2022
Alert CodeICSA-22-349-21
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity/public exploits are available
- Vendor: Siemens
- Equipment: SCALANCE X-200RNA switch devices before V3.2.7
- Vulnerabilities: Observable Timing Discrepancy; Race Condition; Improper Restriction of Operations within the Bounds of a Memory Buffer; Improper Input Validation; NULL Pointer Dereference; Use After Free; Cryptographic Issues; Comparison of Incompatible Types; Resource Management
CISA ICS
Rockwell Automation Stratix 5900
cisa_ics·2017-05-10
Rockwell Automation Stratix 5900
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Rockwell Automation Stratix 5900
Last RevisedMay 10, 2017
Alert CodeICSA-17-094-04
## CVSS v3 10.0
ATTENTION: Remotely exploitable/low skill level to exploit.
Vendor: Rockwell Automation
Equipment: Stratix 5900
Vulnerabilities: Improper Input Validation, Resource Management Errors, Improper Authentication, Path Traversal.
## REPOSTED INFORMATION
This advisory was originally posted to the NCCIC Portal on April 4, 2017, and is being released to the NCCIC/ICS-CERT web site.
## AFFECTED PRODUCTS
Rockwell Automation reports that these vulnerabilities affect the following Strat
Cisco
Multiple Vulnerabilities in OpenSSL (March 2015) Affecting Cisco Products
vendor_cisco·2015-03-20·CVSS 5.0
CVE-2015-0207 [MEDIUM] CWE-119 Multiple Vulnerabilities in OpenSSL (March 2015) Affecting Cisco Products
Multiple Vulnerabilities in OpenSSL (March 2015) Affecting Cisco Products
Multiple Cisco products incorporate a version of the OpenSSL package affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or corrupt portions of OpenSSL process memory. On March 19, 2015, the OpenSSL Project released a security advisory detailing 13 distinct vulnerabilities. The following seven are actively under investigation and the vulnerabilities are referenced in this document as follows:
CVE-2015-0286: OpenSSL ASN1_TYPE_cmp Denial of Service Vulnerability
CVE-2015-0287: OpenSSL ASN.1 Structure Reuse Memory Corruption Vulnerability
CVE-2015-0289: OpenSSL PKCS7 NULL Pointer Dereference Denial of Service Vulnerability
CVE-2015-
Red Hat
openssl: ASN.1 structure reuse memory corruption
vendor_redhat·2015-03-19·CVSS 5.0
CVE-2015-0287 [MEDIUM] CWE-787 openssl: ASN.1 structure reuse memory corruption
openssl: ASN.1 structure reuse memory corruption
The ASN1_item_ex_d2i function in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a does not reinitialize CHOICE and ADB data structures, which might allow attackers to cause a denial of service (invalid write operation and memory corruption) by leveraging an application that relies on ASN.1 structure reuse.
An out-of-bounds write flaw was found in the way OpenSSL reused certain ASN.1 structures. A remote attacker could possibly use a specially crafted ASN.1 structure that, when parsed by an application, would cause that application to crash.
Package: openssl097a (Red Hat Enterprise Linux 5) - Will not fix
Package: openssl098e (Red Hat Enterprise Linux 6) - Will not fix
Pa
BSD
FreeBSD-SA-15:06.openssl: Multiple OpenSSL vulnerabilities
bsd_advisories·2015-03-19·CVSS 6.8
CVE-2015-0204 [MEDIUM] FreeBSD-SA-15:06.openssl: Multiple OpenSSL vulnerabilities
FreeBSD-SA-15:06.openssl Security Advisory
The FreeBSD Project
Topic: Multiple OpenSSL vulnerabilities
Category: contrib
Module: openssl
Announced: 2015-03-19; Last revised on 2015-03-20.
Affects: All supported versions of FreeBSD.
Corrected: 2015-03-20 07:11:20 UTC (stable/10, 10.1-STABLE)
2015-03-20 07:12:02 UTC (releng/10.1, 10.1-RELEASE-p8)
2015-03-20 07:11:20 UTC (stable/9, 9.3-STABLE)
2015-03-20 07:12:02 UTC (releng/9.3, 9.3-RELEASE-p12)
2015-03-20 07:11:20 UTC (stable/8, 8.4-STABLE)
2015-03-20 07:12:02 UTC (releng/8.4, 8.4-RELEASE-p26)
CVE Name: CVE-2015-0209, CVE-2015-0286, CVE-2015-0287, CVE-2015-0288,
CVE-2015-0289, CVE-2015-0293
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following secti
Ubuntu
OpenSSL vulnerabilities
vendor_ubuntu·2015-03-19·CVSS 6.8
CVE-2015-0209 [MEDIUM] OpenSSL vulnerabilities
Title: OpenSSL vulnerabilities
Summary: Several security issues were fixed in OpenSSL.
It was discovered that OpenSSL incorrectly handled malformed EC private key
files. A remote attacker could possibly use this issue to cause OpenSSL to
crash, resulting in a denial of service, or execute arbitrary code.
(CVE-2015-0209)
Stephen Henson discovered that OpenSSL incorrectly handled comparing ASN.1
boolean types. A remote attacker could possibly use this issue to cause
OpenSSL to crash, resulting in a denial of service. (CVE-2015-0286)
Emilia Käsper discovered that OpenSSL incorrectly handled ASN.1 structure
reuse. A remote attacker could possibly use this issue to cause OpenSSL to
crash, resulting in a denial of service, or execute arbitrary code.
(CVE-2015-0287)
Brian Carpenter discovere
Debian
CVE-2015-0287: openssl - The ASN1_item_ex_d2i function in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8z...
vendor_debian·2015·CVSS 5.0
CVE-2015-0287 [MEDIUM] CVE-2015-0287: openssl - The ASN1_item_ex_d2i function in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8z...
The ASN1_item_ex_d2i function in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a does not reinitialize CHOICE and ADB data structures, which might allow attackers to cause a denial of service (invalid write operation and memory corruption) by leveraging an application that relies on ASN.1 structure reuse.
Scope: local
bookworm: resolved (fixed in 1.0.1k-2)
bullseye: resolved (fixed in 1.0.1k-2)
forky: resolved (fixed in 1.0.1k-2)
sid: resolved (fixed in 1.0.1k-2)
trixie: resolved (fixed in 1.0.1k-2)
Cisco
Multiple Vulnerabilities in OpenSSL (March 2015) Affecting Cisco Products
vendor_cisco
CVE-2015-0286 Multiple Vulnerabilities in OpenSSL (March 2015) Affecting Cisco Products
CVE-2015-0286: Multiple Vulnerabilities in OpenSSL (March 2015) Affecting Cisco Products
Multiple Cisco products incorporate a version of the OpenSSL package affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or corrupt portions of OpenSSL process memory. On March 19, 2015, the OpenSSL Project released a security advisory detailing 13 distinct vulnerabilities. The following seven are actively under investigation and the vulnerabilities are referenced in this document as follows: CVE-2015-0286: OpenSSL ASN1_TYPE_cmp Denial of Service Vulnerability CVE-2015-0287: OpenSSL ASN.1 Structure Reuse Memory Corruption Vulnerability CVE-2015-0289: OpenSSL PKCS7 NULL Pointer Dereference Denial of Service Vulnerabili
Cisco
Multiple Vulnerabilities in OpenSSL (March 2015) Affecting Cisco Products
vendor_cisco
CVE-2015-0292 Multiple Vulnerabilities in OpenSSL (March 2015) Affecting Cisco Products
CVE-2015-0292: Multiple Vulnerabilities in OpenSSL (March 2015) Affecting Cisco Products
Multiple Cisco products incorporate a version of the OpenSSL package affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or corrupt portions of OpenSSL process memory. On March 19, 2015, the OpenSSL Project released a security advisory detailing 13 distinct vulnerabilities. The following seven are actively under investigation and the vulnerabilities are referenced in this document as follows: CVE-2015-0286: OpenSSL ASN1_TYPE_cmp Denial of Service Vulnerability CVE-2015-0287: OpenSSL ASN.1 Structure Reuse Memory Corruption Vulnerability CVE-2015-0289: OpenSSL PKCS7 NULL Pointer Dereference Denial of Service Vulnerabili
Cisco
Multiple Vulnerabilities in OpenSSL (March 2015) Affecting Cisco Products
vendor_cisco
CVE-2015-1787 Multiple Vulnerabilities in OpenSSL (March 2015) Affecting Cisco Products
CVE-2015-1787: Multiple Vulnerabilities in OpenSSL (March 2015) Affecting Cisco Products
Multiple Cisco products incorporate a version of the OpenSSL package affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or corrupt portions of OpenSSL process memory. On March 19, 2015, the OpenSSL Project released a security advisory detailing 13 distinct vulnerabilities. The following seven are actively under investigation and the vulnerabilities are referenced in this document as follows: CVE-2015-0286: OpenSSL ASN1_TYPE_cmp Denial of Service Vulnerability CVE-2015-0287: OpenSSL ASN.1 Structure Reuse Memory Corruption Vulnerability CVE-2015-0289: OpenSSL PKCS7 NULL Pointer Dereference Denial of Service Vulnerabili
Cisco
Multiple Vulnerabilities in OpenSSL (March 2015) Affecting Cisco Products
vendor_cisco
CVE-2015-0289 Multiple Vulnerabilities in OpenSSL (March 2015) Affecting Cisco Products
CVE-2015-0289: Multiple Vulnerabilities in OpenSSL (March 2015) Affecting Cisco Products
Multiple Cisco products incorporate a version of the OpenSSL package affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or corrupt portions of OpenSSL process memory. On March 19, 2015, the OpenSSL Project released a security advisory detailing 13 distinct vulnerabilities. The following seven are actively under investigation and the vulnerabilities are referenced in this document as follows: CVE-2015-0286: OpenSSL ASN1_TYPE_cmp Denial of Service Vulnerability CVE-2015-0287: OpenSSL ASN.1 Structure Reuse Memory Corruption Vulnerability CVE-2015-0289: OpenSSL PKCS7 NULL Pointer Dereference Denial of Service Vulnerabili
Apple
CVE-2015-0287: OS X Yosemite v10.10.4 and Security Update 2015-005
vendor_apple·CVSS 5.0
CVE-2015-0287 [MEDIUM] CVE-2015-0287: OS X Yosemite v10.10.4 and Security Update 2015-005
Apple Security Update: About the security content of OS X Yosemite v10.10.4 and Security Update 2015-005
Product: OS X Yosemite v10.10.4 and Security Update 2015-005
CVE: CVE-2015-0287
Component: CVE-2015-0287
Cisco
Multiple Vulnerabilities in OpenSSL (March 2015) Affecting Cisco Products
vendor_cisco
CVE-2015-0288 Multiple Vulnerabilities in OpenSSL (March 2015) Affecting Cisco Products
CVE-2015-0288: Multiple Vulnerabilities in OpenSSL (March 2015) Affecting Cisco Products
Multiple Cisco products incorporate a version of the OpenSSL package affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or corrupt portions of OpenSSL process memory. On March 19, 2015, the OpenSSL Project released a security advisory detailing 13 distinct vulnerabilities. The following seven are actively under investigation and the vulnerabilities are referenced in this document as follows: CVE-2015-0286: OpenSSL ASN1_TYPE_cmp Denial of Service Vulnerability CVE-2015-0287: OpenSSL ASN.1 Structure Reuse Memory Corruption Vulnerability CVE-2015-0289: OpenSSL PKCS7 NULL Pointer Dereference Denial of Service Vulnerabili
Apple
CVE-2015-0287: iOS 9
vendor_apple·CVSS 5.0
CVE-2015-0287 [MEDIUM] CVE-2015-0287: iOS 9
Apple Security Update: About the security content of iOS 9
Product: iOS 9
CVE: CVE-2015-0287
Component: CVE-2015-0287
Cisco
Multiple Vulnerabilities in OpenSSL (March 2015) Affecting Cisco Products
vendor_cisco
CVE-2015-0209 Multiple Vulnerabilities in OpenSSL (March 2015) Affecting Cisco Products
CVE-2015-0209: Multiple Vulnerabilities in OpenSSL (March 2015) Affecting Cisco Products
Multiple Cisco products incorporate a version of the OpenSSL package affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or corrupt portions of OpenSSL process memory. On March 19, 2015, the OpenSSL Project released a security advisory detailing 13 distinct vulnerabilities. The following seven are actively under investigation and the vulnerabilities are referenced in this document as follows: CVE-2015-0286: OpenSSL ASN1_TYPE_cmp Denial of Service Vulnerability CVE-2015-0287: OpenSSL ASN.1 Structure Reuse Memory Corruption Vulnerability CVE-2015-0289: OpenSSL PKCS7 NULL Pointer Dereference Denial of Service Vulnerabili
Cisco
Multiple Vulnerabilities in OpenSSL (March 2015) Affecting Cisco Products
vendor_cisco
CVE-2015-0208 Multiple Vulnerabilities in OpenSSL (March 2015) Affecting Cisco Products
CVE-2015-0208: Multiple Vulnerabilities in OpenSSL (March 2015) Affecting Cisco Products
Multiple Cisco products incorporate a version of the OpenSSL package affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or corrupt portions of OpenSSL process memory. On March 19, 2015, the OpenSSL Project released a security advisory detailing 13 distinct vulnerabilities. The following seven are actively under investigation and the vulnerabilities are referenced in this document as follows: CVE-2015-0286: OpenSSL ASN1_TYPE_cmp Denial of Service Vulnerability CVE-2015-0287: OpenSSL ASN.1 Structure Reuse Memory Corruption Vulnerability CVE-2015-0289: OpenSSL PKCS7 NULL Pointer Dereference Denial of Service Vulnerabili
Cisco
Multiple Vulnerabilities in OpenSSL (March 2015) Affecting Cisco Products
vendor_cisco
CVE-2015-0207 Multiple Vulnerabilities in OpenSSL (March 2015) Affecting Cisco Products
CVE-2015-0207: Multiple Vulnerabilities in OpenSSL (March 2015) Affecting Cisco Products
Multiple Cisco products incorporate a version of the OpenSSL package affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or corrupt portions of OpenSSL process memory. On March 19, 2015, the OpenSSL Project released a security advisory detailing 13 distinct vulnerabilities. The following seven are actively under investigation and the vulnerabilities are referenced in this document as follows: CVE-2015-0286: OpenSSL ASN1_TYPE_cmp Denial of Service Vulnerability CVE-2015-0287: OpenSSL ASN.1 Structure Reuse Memory Corruption Vulnerability CVE-2015-0289: OpenSSL PKCS7 NULL Pointer Dereference Denial of Service Vulnerabili
Cisco
Multiple Vulnerabilities in OpenSSL (March 2015) Affecting Cisco Products
vendor_cisco
CVE-2015-0290 Multiple Vulnerabilities in OpenSSL (March 2015) Affecting Cisco Products
CVE-2015-0290: Multiple Vulnerabilities in OpenSSL (March 2015) Affecting Cisco Products
Multiple Cisco products incorporate a version of the OpenSSL package affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or corrupt portions of OpenSSL process memory. On March 19, 2015, the OpenSSL Project released a security advisory detailing 13 distinct vulnerabilities. The following seven are actively under investigation and the vulnerabilities are referenced in this document as follows: CVE-2015-0286: OpenSSL ASN1_TYPE_cmp Denial of Service Vulnerability CVE-2015-0287: OpenSSL ASN.1 Structure Reuse Memory Corruption Vulnerability CVE-2015-0289: OpenSSL PKCS7 NULL Pointer Dereference Denial of Service Vulnerabili
Cisco
Multiple Vulnerabilities in OpenSSL (March 2015) Affecting Cisco Products
vendor_cisco
CVE-2015-0291 Multiple Vulnerabilities in OpenSSL (March 2015) Affecting Cisco Products
CVE-2015-0291: Multiple Vulnerabilities in OpenSSL (March 2015) Affecting Cisco Products
Multiple Cisco products incorporate a version of the OpenSSL package affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or corrupt portions of OpenSSL process memory. On March 19, 2015, the OpenSSL Project released a security advisory detailing 13 distinct vulnerabilities. The following seven are actively under investigation and the vulnerabilities are referenced in this document as follows: CVE-2015-0286: OpenSSL ASN1_TYPE_cmp Denial of Service Vulnerability CVE-2015-0287: OpenSSL ASN.1 Structure Reuse Memory Corruption Vulnerability CVE-2015-0289: OpenSSL PKCS7 NULL Pointer Dereference Denial of Service Vulnerabili
Cisco
Multiple Vulnerabilities in OpenSSL (March 2015) Affecting Cisco Products
vendor_cisco
CVE-2015-0287 Multiple Vulnerabilities in OpenSSL (March 2015) Affecting Cisco Products
CVE-2015-0287: Multiple Vulnerabilities in OpenSSL (March 2015) Affecting Cisco Products
Multiple Cisco products incorporate a version of the OpenSSL package affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or corrupt portions of OpenSSL process memory. On March 19, 2015, the OpenSSL Project released a security advisory detailing 13 distinct vulnerabilities. The following seven are actively under investigation and the vulnerabilities are referenced in this document as follows: CVE-2015-0286: OpenSSL ASN1_TYPE_cmp Denial of Service Vulnerability CVE-2015-0287: OpenSSL ASN.1 Structure Reuse Memory Corruption Vulnerability CVE-2015-0289: OpenSSL PKCS7 NULL Pointer Dereference Denial of Service Vulnerabili
Apple
CVE-2015-0287: OS X El Capitan v10.11
vendor_apple·CVSS 5.0
CVE-2015-0287 [MEDIUM] CVE-2015-0287: OS X El Capitan v10.11
Apple Security Update: About the security content of OS X El Capitan v10.11
Product: OS X El Capitan v10.11
CVE: CVE-2015-0287
Component: CVE-2015-0287
Impact: Multiple vulnerabilities in procmail
Description: Multiple vulnerabilities existed in procmail versions prior to 3.22. These issues were addressed by removing procmail.
Cisco
Multiple Vulnerabilities in OpenSSL (March 2015) Affecting Cisco Products
vendor_cisco
CVE-2015-0285 Multiple Vulnerabilities in OpenSSL (March 2015) Affecting Cisco Products
CVE-2015-0285: Multiple Vulnerabilities in OpenSSL (March 2015) Affecting Cisco Products
Multiple Cisco products incorporate a version of the OpenSSL package affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or corrupt portions of OpenSSL process memory. On March 19, 2015, the OpenSSL Project released a security advisory detailing 13 distinct vulnerabilities. The following seven are actively under investigation and the vulnerabilities are referenced in this document as follows: CVE-2015-0286: OpenSSL ASN1_TYPE_cmp Denial of Service Vulnerability CVE-2015-0287: OpenSSL ASN.1 Structure Reuse Memory Corruption Vulnerability CVE-2015-0289: OpenSSL PKCS7 NULL Pointer Dereference Denial of Service Vulnerabili
Cisco
Multiple Vulnerabilities in OpenSSL (March 2015) Affecting Cisco Products
vendor_cisco
CVE-2015-0293 Multiple Vulnerabilities in OpenSSL (March 2015) Affecting Cisco Products
CVE-2015-0293: Multiple Vulnerabilities in OpenSSL (March 2015) Affecting Cisco Products
Multiple Cisco products incorporate a version of the OpenSSL package affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or corrupt portions of OpenSSL process memory. On March 19, 2015, the OpenSSL Project released a security advisory detailing 13 distinct vulnerabilities. The following seven are actively under investigation and the vulnerabilities are referenced in this document as follows: CVE-2015-0286: OpenSSL ASN1_TYPE_cmp Denial of Service Vulnerability CVE-2015-0287: OpenSSL ASN.1 Structure Reuse Memory Corruption Vulnerability CVE-2015-0289: OpenSSL PKCS7 NULL Pointer Dereference Denial of Service Vulnerabili
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-0209 CVE-2015-0293 CVE-2015-0287 CVE-2015-0286 CVE-2015-0289 CVE-2015-0288 mingw-openssl: various flaws [epel-7]
bugzilla·2015-03-19·CVSS 6.8
CVE-2015-0209 [MEDIUM] CVE-2015-0209 CVE-2015-0293 CVE-2015-0287 CVE-2015-0286 CVE-2015-0289 CVE-2015-0288 mingw-openssl: various flaws [epel-7]
CVE-2015-0209 CVE-2015-0293 CVE-2015-0287 CVE-2015-0286 CVE-2015-0289 CVE-2015-0288 mingw-openssl: various flaws [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
epel-7
Bugzilla
CVE-2015-0209 CVE-2015-0293 CVE-2015-0287 CVE-2015-0286 CVE-2015-0289 CVE-2015-0288 mingw-openssl: various flaws [fedora-all]
bugzilla·2015-03-19·CVSS 6.8
CVE-2015-0209 [MEDIUM] CVE-2015-0209 CVE-2015-0293 CVE-2015-0287 CVE-2015-0286 CVE-2015-0289 CVE-2015-0288 mingw-openssl: various flaws [fedora-all]
CVE-2015-0209 CVE-2015-0293 CVE-2015-0287 CVE-2015-0286 CVE-2015-0289 CVE-2015-0288 mingw-openssl: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: th
Bugzilla
CVE-2015-0287 openssl: ASN.1 structure reuse memory corruption
bugzilla·2015-03-16·CVSS 5.0
CVE-2015-0287 [MEDIUM] CVE-2015-0287 openssl: ASN.1 structure reuse memory corruption
CVE-2015-0287 openssl: ASN.1 structure reuse memory corruption
Reusing a structure in ASN.1 parsing may allow an attacker to cause memory corruption via an invalid write. Such reuse is and has been strongly discouraged and is believed to be rare.
Applications that parse structures containing CHOICE or ANY DEFINED BY components may be affected. Certificate parsing (d2i_X509 and related functions) are however not affected. OpenSSL clients and servers are not affected.
This issue affects OpenSSL versions: 1.0.2, 1.0.1, 1.0.0, and 0.9.8. This issue is fixed in versions: 1.0.2a, 1.0.1m, 1.0.0r, and 0.9.8zf.
Acknowledgements:
Red Hat would like to thank the OpenSSL project for reporting this issue. Upstream acknowledges Emilia Käsper as the original reporter.
Discussion:
External Referenc
Bugzilla
CVE-2015-0292 CVE-2015-0209 CVE-2015-0287 CVE-2015-0286 CVE-2015-0289 CVE-2015-0288 openssl: various flaws [fedora-all]
bugzilla·2015-02-26·CVSS 6.8
CVE-2015-0292 [MEDIUM] CVE-2015-0292 CVE-2015-0209 CVE-2015-0287 CVE-2015-0286 CVE-2015-0289 CVE-2015-0288 openssl: various flaws [fedora-all]
CVE-2015-0292 CVE-2015-0209 CVE-2015-0287 CVE-2015-0286 CVE-2015-0289 CVE-2015-0288 openssl: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this iss
Tenable
[R3] LCE 5.0.0 Fixes Multiple Third-party Library Vulnerabilities
blogs_tenable·2017-01-31
[R3] LCE 5.0.0 Fixes Multiple Third-party Library Vulnerabilities
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
[R6] OpenSSL '20150319' Advisory Affects Tenable Products
blogs_tenable·2015-03-29
[R6] OpenSSL '20150319' Advisory Affects Tenable Products
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
arXiv
Asteria-Pro: Enhancing Deep-Learning Based Binary Code Similarity Detection by Incorporating Domain Knowledge
arxiv_fulltext·2023-05-22
Asteria-Pro: Enhancing Deep-Learning Based Binary Code Similarity Detection by Incorporating Domain Knowledge
Asteria-Pro: Enhancing Deep-Learning Based Binary Code Similarity Detection by Incorporating Domain Knowledge
Shouguo Yang
First Author and Second Author contribute equally to this work.
Institute of Information Engineering, Chinese Academy of Sciences
Beijing
China
School of Cyber Security, University of Chinese Academy of Sciences
Beijing
China
[email protected]
Chaopeng Dong
Institute of Information Engineering, Chinese Academy of Sciences
Beijing
China
School of Cyber Security, University of Chinese Academy of Sciences
Beijing
China
[email protected]
[1]
Yang Xiao
Institute of Information Engineering, Chinese Academy of Sciences
Beijing
China
School of Cyber Security, University of Chinese Academy of Sciences
Beijing
China
[email protected]
Corresponding authors.
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10680http://lists.apple.com/archives/security-announce/2015/Jun/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2015/Sep/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2015/Sep/msg00008.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-March/152733.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-March/152734.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-March/152844.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-May/156823.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-May/157177.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00022.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00027.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00037.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00017.htmlhttp://lists.opensuse.org/opensuse-updates/2015-03/msg00062.htmlhttp://marc.info/?l=bugtraq&m=142841429220765&w=2http://marc.info/?l=bugtraq&m=143213830203296&w=2http://marc.info/?l=bugtraq&m=143748090628601&w=2http://marc.info/?l=bugtraq&m=144050155601375&w=2http://marc.info/?l=bugtraq&m=144050297101809&w=2http://rhn.redhat.com/errata/RHSA-2015-0715.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0716.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0752.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0800.htmlhttp://support.apple.com/kb/HT204942http://www.debian.org/security/2015/dsa-3197http://www.mandriva.com/security/advisories?name=MDVSA-2015:062http://www.mandriva.com/security/advisories?name=MDVSA-2015:063http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.htmlhttp://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.htmlhttp://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.htmlhttp://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.htmlhttp://www.securityfocus.com/bid/73227http://www.securitytracker.com/id/1031929http://www.ubuntu.com/usn/USN-2537-1https://access.redhat.com/articles/1384453https://bto.bluecoat.com/security-advisory/sa92https://bugzilla.redhat.com/show_bug.cgi?id=1202380https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdfhttps://git.openssl.org/?p=openssl.git%3Ba=commit%3Bh=b717b083073b6cacc0a5e2397b661678aff7ae7fhttps://kc.mcafee.com/corporate/index?page=content&id=SB10110https://security.gentoo.org/glsa/201503-11https://support.apple.com/HT205212https://support.apple.com/HT205267https://support.citrix.com/article/CTX216642https://www.freebsd.org/security/advisories/FreeBSD-SA-15%3A06.openssl.aschttps://www.openssl.org/news/secadv_20150319.txthttp://kb.juniper.net/InfoCenter/index?page=content&id=JSA10680http://lists.apple.com/archives/security-announce/2015/Jun/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2015/Sep/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2015/Sep/msg00008.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-March/152733.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-March/152734.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-March/152844.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-May/156823.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-May/157177.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00022.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00027.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00037.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00017.htmlhttp://lists.opensuse.org/opensuse-updates/2015-03/msg00062.htmlhttp://marc.info/?l=bugtraq&m=142841429220765&w=2http://marc.info/?l=bugtraq&m=143213830203296&w=2http://marc.info/?l=bugtraq&m=143748090628601&w=2http://marc.info/?l=bugtraq&m=144050155601375&w=2http://marc.info/?l=bugtraq&m=144050297101809&w=2http://rhn.redhat.com/errata/RHSA-2015-0715.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0716.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0752.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0800.htmlhttp://support.apple.com/kb/HT204942http://www.debian.org/security/2015/dsa-3197http://www.mandriva.com/security/advisories?name=MDVSA-2015:062http://www.mandriva.com/security/advisories?name=MDVSA-2015:063http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.htmlhttp://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.htmlhttp://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.htmlhttp://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.htmlhttp://www.securityfocus.com/bid/73227http://www.securitytracker.com/id/1031929http://www.ubuntu.com/usn/USN-2537-1https://access.redhat.com/articles/1384453https://bto.bluecoat.com/security-advisory/sa92https://bugzilla.redhat.com/show_bug.cgi?id=1202380https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdfhttps://git.openssl.org/?p=openssl.git%3Ba=commit%3Bh=b717b083073b6cacc0a5e2397b661678aff7ae7fhttps://kc.mcafee.com/corporate/index?page=content&id=SB10110https://security.gentoo.org/glsa/201503-11https://support.apple.com/HT205212https://support.apple.com/HT205267https://support.citrix.com/article/CTX216642https://www.freebsd.org/security/advisories/FreeBSD-SA-15%3A06.openssl.aschttps://www.openssl.org/news/secadv_20150319.txt
2015-03-19
Published