CVE-2015-1788Improper Restriction of Operations within the Bounds of a Memory Buffer in Openssl

Severity
4.3MEDIUMNVD
OSV7.5
EPSS
15.9%
top 5.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 12
Latest updateDec 19

Description

The BN_GF2m_mod_inv function in crypto/bn/bn_gf2m.c in OpenSSL before 0.9.8s, 1.0.0 before 1.0.0e, 1.0.1 before 1.0.1n, and 1.0.2 before 1.0.2b does not properly handle ECParameters structures in which the curve is over a malformed binary polynomial field, which allows remote attackers to cause a denial of service (infinite loop) via a session that uses an Elliptic Curve algorithm, as demonstrated by an attack against a server that supports client authentication.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages7 packages

debiandebian/openssl< openssl 1.0.2b-1 (bookworm)
Debianopenssl/openssl< 1.0.2b-1+3
Ubuntuopenssl/openssl< 1.0.1f-1ubuntu2.15
NVDopenssl/openssl0.9.8zf+35

🔴Vulnerability Details

3
GHSA
GHSA-r4h7-cp79-4cmq: The BN_GF2m_mod_inv function in crypto/bn/bn_gf2m2022-05-17
OSV
CVE-2015-1788: The BN_GF2m_mod_inv function in crypto/bn/bn_gf2m2015-06-12
OSV
openssl vulnerabilities2015-06-11

📋Vendor Advisories

10
CISA ICS
Siemens SCALANCE X-200RNA Switch Devices2022-12-19
Palo Alto
PAN-SA-2016-0028 OpenSSL Vulnerabilities2016-10-18
Palo Alto
PAN-SA-2016-0020 OpenSSL Vulnerabilities2016-08-15
Cisco
Multiple Vulnerabilities in OpenSSL (June 2015) Affecting Cisco Products2015-06-12
BSD
FreeBSD-SA-15:10.openssl: Multiple OpenSSL vulnerabilities2015-06-12

🕵️Threat Intelligence

2
Tenable
[R3] LCE 5.0.0 Fixes Multiple Third-party Library Vulnerabilities2017-01-31
Tenable
[R7] OpenSSL &#039;20150611&#039; Advisory Affects Tenable Products2015-06-30

💬Community

3
Bugzilla
CVE-2015-1333 kernel: denial of service due to memory leak in add_key()2015-07-22
HackerOne
Malformed ECParameters causes infinite loop2015-06-11
Bugzilla
CVE-2015-1788 OpenSSL: Malformed ECParameters causes infinite loop2015-06-05
CVE-2015-1788 — Debian Openssl vulnerability | cvebase