CVE-2015-3194NULL Pointer Dereference in Openssl

Severity
7.5HIGHNVD
EPSS
51.9%
top 2.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 6
Latest updateNov 7

Description

crypto/rsa/rsa_ameth.c in OpenSSL 1.0.1 before 1.0.1q and 1.0.2 before 1.0.2e allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an RSA PSS ASN.1 signature that lacks a mask generation function parameter.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

Debianopenssl/openssl< 1.0.2e-1+3
NVDopenssl/openssl22 versions+21
NVDnodejs/node.js0.10.00.10.41+3

Also affects: Debian Linux 7.0, 8.0, Ubuntu Linux 12.04, 14.04, 15.04, 15.10

Patches

🔴Vulnerability Details

3
GHSA
GHSA-g2vh-4463-xcx8: crypto/rsa/rsa_ameth2022-05-14
CVEList
CVE-2015-3194: crypto/rsa/rsa_ameth2015-12-06
OSV
CVE-2015-3194: crypto/rsa/rsa_ameth2015-12-06

📋Vendor Advisories

8
Palo Alto
PAN-SA-2024-0014 Informational Bulletin: Impact of OSS CVEs in Cortex XDR Agent2024-11-07
Apple
CVE-2015-3194: macOS Mojave 10.142018-09-24
Apple
CVE-2015-3194: Xcode 8.12016-10-27
Red Hat
OpenSSL: Certificate verify crash with missing PSS parameter2016-01-28
Ubuntu
OpenSSL vulnerabilities2015-12-07

💬Community

2
Bugzilla
CVE-2015-3194 CVE-2015-3195 CVE-2015-3196 mingw-openssl: various flaws [fedora-all]2015-12-10
Bugzilla
CVE-2015-3194 OpenSSL: Certificate verify crash with missing PSS parameter2015-12-04