cbcvebase.
CVE-2015-3195
published 2015-12-06

CVE-2015-3195: The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1q, and 1.0.2 before 1.0.2e…

PriorityP341medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
38.71%
98.4th percentile
The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1q, and 1.0.2 before 1.0.2e mishandles errors caused by malformed X509_ATTRIBUTE data, which allows remote attackers to obtain sensitive information from process memory by triggering a decoding failure in a PKCS#7 or CMS application.

Affected

65 ranges· showing 25
VendorProductVersion rangeFixed in
applemac_os_x< 10.11.410.11.4
appleos_x_el_capitan_v10.11.4_and_security_update_2016-002
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
ciscoproducts
debiandebian_linux
debiandebian_linux
debianopenssl< openssl 1.0.2e-1 (bookworm)openssl 1.0.2e-1 (bookworm)
fedoraprojectfedora
opensslopenssl< 0.9.8zh0.9.8zh
opensslopenssl>= 0 < 1.0.2e-11.0.2e-1
opensslopenssl>= 0 < 1.0.2e-11.0.2e-1
opensslopenssl>= 0 < 1.0.2e-11.0.2e-1
opensslopenssl>= 0 < 1.0.2e-11.0.2e-1
opensslopenssl>= 0 < 1.0.1f-1ubuntu2.161.0.1f-1ubuntu2.16
opensslopenssl>= 1.0.0 < 1.0.0t1.0.0t
opensslopenssl>= 1.0.1 < 1.0.1q1.0.1q
opensslopenssl>= 1.0.2 < 1.0.2e1.0.2e
opensuseleap
opensuseopensuse
opensuseopensuse
opensuseopensuse
oracleapi_gateway

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.