CVE-2015-3195
published 2015-12-06CVE-2015-3195: The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1q, and 1.0.2 before 1.0.2e…
PriorityP341medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
38.71%
98.4th percentile
The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1q, and 1.0.2 before 1.0.2e mishandles errors caused by malformed X509_ATTRIBUTE data, which allows remote attackers to obtain sensitive information from process memory by triggering a decoding failure in a PKCS#7 or CMS application.
Affected
65 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | < 10.11.4 | 10.11.4 |
| apple | os_x_el_capitan_v10.11.4_and_security_update_2016-002 | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| cisco | products | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | openssl | < openssl 1.0.2e-1 (bookworm) | openssl 1.0.2e-1 (bookworm) |
| fedoraproject | fedora | — | — |
| openssl | openssl | < 0.9.8zh | 0.9.8zh |
| openssl | openssl | >= 0 < 1.0.2e-1 | 1.0.2e-1 |
| openssl | openssl | >= 0 < 1.0.2e-1 | 1.0.2e-1 |
| openssl | openssl | >= 0 < 1.0.2e-1 | 1.0.2e-1 |
| openssl | openssl | >= 0 < 1.0.2e-1 | 1.0.2e-1 |
| openssl | openssl | >= 0 < 1.0.1f-1ubuntu2.16 | 1.0.1f-1ubuntu2.16 |
| openssl | openssl | >= 1.0.0 < 1.0.0t | 1.0.0t |
| openssl | openssl | >= 1.0.1 < 1.0.1q | 1.0.1q |
| openssl | openssl | >= 1.0.2 < 1.0.2e | 1.0.2e |
| opensuse | leap | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| oracle | api_gateway | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7q2f-v729-wjf3: The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec
ghsa_unreviewed·2022-05-13
CVE-2015-3195 [MEDIUM] CWE-200 GHSA-7q2f-v729-wjf3: The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec
The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1q, and 1.0.2 before 1.0.2e mishandles errors caused by malformed X509_ATTRIBUTE data, which allows remote attackers to obtain sensitive information from process memory by triggering a decoding failure in a PKCS#7 or CMS application.
OSV
openssl vulnerabilities
osv·2015-12-07·CVSS 5.0
CVE-2015-1794 [MEDIUM] openssl vulnerabilities
openssl vulnerabilities
Guy Leaver discovered that OpenSSL incorrectly handled a ServerKeyExchange
for an anonymous DH ciphersuite with the value of p set to 0. A remote
attacker could possibly use this issue to cause OpenSSL to crash, resulting
in a denial of service. This issue only applied to Ubuntu 15.10.
(CVE-2015-1794)
Hanno Böck discovered that the OpenSSL Montgomery squaring procedure
algorithm may produce incorrect results when being used on x86_64. A remote
attacker could possibly use this issue to break encryption. This issue only
applied to Ubuntu 15.10. (CVE-2015-3193)
Loïc Jonas Etienne discovered that OpenSSL incorrectly handled ASN.1
signatures with a missing PSS parameter. A remote attacker could possibly
use this issue to cause OpenSSL to crash, resulting in a denial o
OSV
CVE-2015-3195: The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec
osv·2015-12-06·CVSS 5.3
CVE-2015-3195 [MEDIUM] CVE-2015-3195: The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec
The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1q, and 1.0.2 before 1.0.2e mishandles errors caused by malformed X509_ATTRIBUTE data, which allows remote attackers to obtain sensitive information from process memory by triggering a decoding failure in a PKCS#7 or CMS application.
CISA ICS
Siemens SCALANCE X-200RNA Switch Devices
cisa_ics·2022-12-19
Siemens SCALANCE X-200RNA Switch Devices
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SCALANCE X-200RNA Switch Devices
Last RevisedDecember 19, 2022
Alert CodeICSA-22-349-21
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity/public exploits are available
- Vendor: Siemens
- Equipment: SCALANCE X-200RNA switch devices before V3.2.7
- Vulnerabilities: Observable Timing Discrepancy; Race Condition; Improper Restriction of Operations within the Bounds of a Memory Buffer; Improper Input Validation; NULL Pointer Dereference; Use After Free; Cryptographic Issues; Comparison of Incompatible Types; Resource Management
Palo Alto
PAN-SA-2016-0020 OpenSSL Vulnerabilities
vendor_paloalto·2016-08-15·CVSS 7.5
CVE-2014-8176 [HIGH] CWE-119 PAN-SA-2016-0020 OpenSSL Vulnerabilities
PAN-SA-2016-0020 OpenSSL Vulnerabilities
The OpenSSL library has been found to contain several vulnerabilities CVE-2014-8176, CVE-2015-1788, CVE-2015-1789, CVE-2015-1790, CVE-2015-1791, CVE-2015-1792, CVE-2015-1794, CVE-2015-3195, CVE-2015-4000, CVE-2016-2105, CVE-2016-2106, CVE-2016-2107, CVE-2016-2108, CVE-2016-2109, CVE-2016-2176, CVE-2016-2842. Palo Alto Networks software makes use of the vulnerable library. (Ref # 95622). The OpenSSL library in use by PAN-OS is patched on a regular basis. Severities of the CVEs listed under the summary section range from low to high but, have not been shown to be exploitable at the time of this advisory. This issue affects PAN-OS 5.0.X; PAN-OS-5.1.X; PAN-OS 6.0.13 and earlier; PAN-OS 6.1.12 and earlier; PAN-OS 7.0.8 and earlier; PAN-OS 7.1.3 and earl
Ubuntu
OpenSSL vulnerabilities
vendor_ubuntu·2015-12-07·CVSS 5.0
CVE-2015-1794 [MEDIUM] OpenSSL vulnerabilities
Title: OpenSSL vulnerabilities
Summary: Several security issues were fixed in OpenSSL.
Guy Leaver discovered that OpenSSL incorrectly handled a ServerKeyExchange
for an anonymous DH ciphersuite with the value of p set to 0. A remote
attacker could possibly use this issue to cause OpenSSL to crash, resulting
in a denial of service. This issue only applied to Ubuntu 15.10.
(CVE-2015-1794)
Hanno Böck discovered that the OpenSSL Montgomery squaring procedure
algorithm may produce incorrect results when being used on x86_64. A remote
attacker could possibly use this issue to break encryption. This issue only
applied to Ubuntu 15.10. (CVE-2015-3193)
Loïc Jonas Etienne discovered that OpenSSL incorrectly handled ASN.1
signatures with a missing PSS parameter. A remote attacker could possibly
u
BSD
FreeBSD-SA-15:26.openssl: Multiple OpenSSL vulnerabilities
bsd_advisories·2015-12-06·CVSS 7.5
CVE-2015-3194 [HIGH] FreeBSD-SA-15:26.openssl: Multiple OpenSSL vulnerabilities
FreeBSD-SA-15:26.openssl Security Advisory
The FreeBSD Project
Topic: Multiple OpenSSL vulnerabilities
Category: contrib
Module: openssl
Announced: 2015-12-05
Affects: All supported versions of FreeBSD.
Corrected: 2015-12-03 21:18:48 UTC (stable/10, 10.2-STABLE)
2015-12-05 09:53:58 UTC (releng/10.2, 10.2-RELEASE-p8)
2015-12-05 09:53:58 UTC (releng/10.1, 10.1-RELEASE-p25)
2015-12-03 21:24:40 UTC (stable/9, 9.3-STABLE)
2015-12-05 09:53:58 UTC (releng/9.3, 9.3-RELEASE-p31)
CVE Name: CVE-2015-3194, CVE-2015-3195, CVE-2015-3196
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit .
I. Background
FreeBSD includes software from the OpenSSL Project. The OpenSSL Project is
a collab
Cisco
Multiple Vulnerabilities in OpenSSL (December 2015) Affecting Cisco Products
vendor_cisco·2015-12-04
CVE-2015-1794 [MEDIUM] CWE-399 Multiple Vulnerabilities in OpenSSL (December 2015) Affecting Cisco Products
Multiple Vulnerabilities in OpenSSL (December 2015) Affecting Cisco Products
On December 3, 2015, the OpenSSL Project released a security advisory detailing five vulnerabilities.
Multiple Cisco products incorporate a version of the OpenSSL package affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
This advisory will be updated as additional information becomes available.
Cisco will release software updates that address these vulnerabilities.
Workarounds that mitigate these vulnerabilities are not available.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151204-openssl
Red Hat
OpenSSL: X509_ATTRIBUTE memory leak
vendor_redhat·2015-12-03·CVSS 5.3
CVE-2015-3195 [MEDIUM] CWE-401 OpenSSL: X509_ATTRIBUTE memory leak
OpenSSL: X509_ATTRIBUTE memory leak
The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1q, and 1.0.2 before 1.0.2e mishandles errors caused by malformed X509_ATTRIBUTE data, which allows remote attackers to obtain sensitive information from process memory by triggering a decoding failure in a PKCS#7 or CMS application.
A memory leak vulnerability was found in the way OpenSSL parsed PKCS#7 and CMS data. A remote attacker could use this flaw to cause an application that parses PKCS#7 or CMS data from untrusted sources to use an excessive amount of memory and possibly crash.
Package: openssl097a (Red Hat Enterprise Linux 5) - Not affected
Package: openssl098e (Red Hat Enterprise Linux 6) - Will not fix
Package:
Debian
CVE-2015-3195: openssl - The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before...
vendor_debian·2015·CVSS 5.3
CVE-2015-3195 [MEDIUM] CVE-2015-3195: openssl - The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before...
The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1q, and 1.0.2 before 1.0.2e mishandles errors caused by malformed X509_ATTRIBUTE data, which allows remote attackers to obtain sensitive information from process memory by triggering a decoding failure in a PKCS#7 or CMS application.
Scope: local
bookworm: resolved (fixed in 1.0.2e-1)
bullseye: resolved (fixed in 1.0.2e-1)
forky: resolved (fixed in 1.0.2e-1)
sid: resolved (fixed in 1.0.2e-1)
trixie: resolved (fixed in 1.0.2e-1)
Cisco
Multiple Vulnerabilities in OpenSSL (December 2015) Affecting Cisco Products
vendor_cisco
CVE-2015-3195 Multiple Vulnerabilities in OpenSSL (December 2015) Affecting Cisco Products
CVE-2015-3195: Multiple Vulnerabilities in OpenSSL (December 2015) Affecting Cisco Products
On December 3, 2015, the OpenSSL Project released a security advisory detailing five vulnerabilities. Multiple Cisco products incorporate a version of the OpenSSL package affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This advisory will be updated as additional information becomes available. Cisco will release software updates that address these vulnerabilities.
CWE: CWE-399, CWE-399
Bug IDs: CSCux41145, CSCux41206, CSCux41294, CSCux41145, CSCux41206
Apple
CVE-2015-3195: OS X El Capitan v10.11.4 and Security Update 2016-002
vendor_apple·CVSS 5.3
CVE-2015-3195 [MEDIUM] CVE-2015-3195: OS X El Capitan v10.11.4 and Security Update 2016-002
Apple Security Update: About the security content of OS X El Capitan v10.11.4 and Security Update 2016-002
Product: OS X El Capitan v10.11.4 and Security Update 2016-002
CVE: CVE-2015-3195
Component: CVE-2015-3195
No detection rules found.
No public exploits indexed.
Tenable
[R3] LCE 5.0.0 Fixes Multiple Third-party Library Vulnerabilities
blogs_tenable·2017-01-31
[R3] LCE 5.0.0 Fixes Multiple Third-party Library Vulnerabilities
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
[R7] OpenSSL '20151203' Advisory Affects Tenable SecurityCenter
blogs_tenable·2016-01-06
[R7] OpenSSL '20151203' Advisory Affects Tenable SecurityCenter
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bugzilla
CVE-2015-3194 CVE-2015-3195 CVE-2015-3196 mingw-openssl: various flaws [fedora-all]
bugzilla·2015-12-10·CVSS 7.5
CVE-2015-3194 [HIGH] CVE-2015-3194 CVE-2015-3195 CVE-2015-3196 mingw-openssl: various flaws [fedora-all]
CVE-2015-3194 CVE-2015-3195 CVE-2015-3196 mingw-openssl: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versio
Bugzilla
CVE-2015-3195 OpenSSL: X509_ATTRIBUTE memory leak
bugzilla·2015-12-04·CVSS 5.3
CVE-2015-3195 [MEDIUM] CVE-2015-3195 OpenSSL: X509_ATTRIBUTE memory leak
CVE-2015-3195 OpenSSL: X509_ATTRIBUTE memory leak
The following was reported by OpenSSL upstream:
When presented with a malformed X509_ATTRIBUTE structure OpenSSL will leak memory. This structure is used by the PKCS#7 and CMS routines so any application which reads PKCS#7 or CMS data from untrusted sources is affected. SSL/TLS is not affected.
This issue affects OpenSSL versions 1.0.2 and 1.0.1, 1.0.0 and 0.9.8.
OpenSSL 1.0.2 users should upgrade to 1.0.2e
OpenSSL 1.0.1 users should upgrade to 1.0.1q
OpenSSL 1.0.0 users should upgrade to 1.0.0t
OpenSSL 0.9.8 users should upgrade to 0.9.8zh
This issue was reported to OpenSSL on November 9 2015 by Adam Langley (Google/BoringSSL) using libFuzzer. The fix was developed by Dr. Stephen
Henson of the OpenSSL development team.
Discussion:
http://fortiguard.com/advisory/openssl-advisory-december-2015http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10733http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10759http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761http://lists.apple.com/archives/security-announce/2016/Mar/msg00004.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-December/173801.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00017.htmlhttp://lists.opensuse.org/opensuse-updates/2015-12/msg00070.htmlhttp://lists.opensuse.org/opensuse-updates/2015-12/msg00071.htmlhttp://lists.opensuse.org/opensuse-updates/2015-12/msg00087.htmlhttp://lists.opensuse.org/opensuse-updates/2015-12/msg00103.htmlhttp://marc.info/?l=bugtraq&m=145382583417444&w=2http://openssl.org/news/secadv/20151203.txthttp://rhn.redhat.com/errata/RHSA-2015-2616.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2617.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2056.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2957.htmlhttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151204-opensslhttp://www.debian.org/security/2015/dsa-3413http://www.fortiguard.com/advisory/openssl-advisory-december-2015http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.htmlhttp://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/78626http://www.securityfocus.com/bid/91787http://www.securitytracker.com/id/1034294http://www.slackware.com/security/viewer.php?l=slackware-security&y=2015&m=slackware-security.754583http://www.ubuntu.com/usn/USN-2830-1https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdfhttps://git.openssl.org/?p=openssl.git%3Ba=commit%3Bh=cc598f321fbac9c04da5766243ed55d55948637dhttps://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04944173https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05111017https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05131085https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05150888https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05158380https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05398322https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA40100https://support.apple.com/HT206167http://fortiguard.com/advisory/openssl-advisory-december-2015http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10733http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10759http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761http://lists.apple.com/archives/security-announce/2016/Mar/msg00004.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-December/173801.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00017.htmlhttp://lists.opensuse.org/opensuse-updates/2015-12/msg00070.htmlhttp://lists.opensuse.org/opensuse-updates/2015-12/msg00071.htmlhttp://lists.opensuse.org/opensuse-updates/2015-12/msg00087.htmlhttp://lists.opensuse.org/opensuse-updates/2015-12/msg00103.htmlhttp://marc.info/?l=bugtraq&m=145382583417444&w=2http://openssl.org/news/secadv/20151203.txthttp://rhn.redhat.com/errata/RHSA-2015-2616.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2617.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2056.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2957.htmlhttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151204-opensslhttp://www.debian.org/security/2015/dsa-3413http://www.fortiguard.com/advisory/openssl-advisory-december-2015http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.htmlhttp://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/78626http://www.securityfocus.com/bid/91787http://www.securitytracker.com/id/1034294http://www.slackware.com/security/viewer.php?l=slackware-security&y=2015&m=slackware-security.754583http://www.ubuntu.com/usn/USN-2830-1https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdfhttps://git.openssl.org/?p=openssl.git%3Ba=commit%3Bh=cc598f321fbac9c04da5766243ed55d55948637dhttps://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04944173https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05111017https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05131085https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05150888https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05158380https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05398322https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA40100https://support.apple.com/HT206167
2015-12-06
Published