CVE-2015-0289Improper Restriction of Operations within the Bounds of a Memory Buffer in Openssl

Severity
5.0MEDIUMNVD
OSV6.8
EPSS
5.8%
top 9.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 19
Latest updateDec 19

Description

The PKCS#7 implementation in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a does not properly handle a lack of outer ContentInfo, which allows attackers to cause a denial of service (NULL pointer dereference and application crash) by leveraging an application that processes arbitrary PKCS#7 data and providing malformed data with ASN.1 encoding, related to crypto/pkcs7/pk7_doit.c and crypto/pkcs7/pk7_lib.c.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages6 packages

debiandebian/openssl< openssl 1.0.1k-2 (bookworm)
Debianopenssl/openssl< 1.0.1k-2+3
Ubuntuopenssl/openssl< 1.0.1f-1ubuntu2.11
NVDopenssl/openssl0.9.8ze+32

🔴Vulnerability Details

3
GHSA
GHSA-cxc6-qvvg-mcqm: The PKCS#7 implementation in OpenSSL before 02022-05-17
OSV
openssl vulnerabilities2015-03-19
OSV
CVE-2015-0289: The PKCS#7 implementation in OpenSSL before 02015-03-19

📋Vendor Advisories

21
CISA ICS
Siemens SCALANCE X-200RNA Switch Devices2022-12-19
CISA ICS
Rockwell Automation Stratix 59002017-05-10
Cisco
Multiple Vulnerabilities in OpenSSL (March 2015) Affecting Cisco Products2015-03-20
Red Hat
openssl: PKCS7 NULL pointer dereference2015-03-19
BSD
FreeBSD-SA-15:06.openssl: Multiple OpenSSL vulnerabilities2015-03-19

🕵️Threat Intelligence

1
Tenable
[R6] OpenSSL &#039;20150319&#039; Advisory Affects Tenable Products2015-03-29

💬Community

4
Bugzilla
CVE-2015-0209 CVE-2015-0293 CVE-2015-0287 CVE-2015-0286 CVE-2015-0289 CVE-2015-0288 mingw-openssl: various flaws [epel-7]2015-03-19
Bugzilla
CVE-2015-0209 CVE-2015-0293 CVE-2015-0287 CVE-2015-0286 CVE-2015-0289 CVE-2015-0288 mingw-openssl: various flaws [fedora-all]2015-03-19
Bugzilla
CVE-2015-0289 openssl: PKCS7 NULL pointer dereference2015-03-16
Bugzilla
CVE-2015-0292 CVE-2015-0209 CVE-2015-0287 CVE-2015-0286 CVE-2015-0289 CVE-2015-0288 openssl: various flaws [fedora-all]2015-02-26
CVE-2015-0289 — Debian Openssl vulnerability | cvebase