CVE-2015-5333
published 2020-01-23CVE-2015-5333: Memory leak in the OBJ_obj2txt function in LibreSSL before 2.3.1 allows remote attackers to cause a denial of service (memory consumption) via a large number…
PriorityP432high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.98%
78.3th percentile
Memory leak in the OBJ_obj2txt function in LibreSSL before 2.3.1 allows remote attackers to cause a denial of service (memory consumption) via a large number of ASN.1 object identifiers in X.509 certificates.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos_mojave | — | — |
| apple | os_x_el_capitan_10.11.2_security_update_2015-005_yosemite_and_security_update_20 | — | — |
| apple | os_x_el_capitan_v10.11.4_and_security_update_2016-002 | — | — |
| libressl | libressl | — | — |
| openbsd | libressl | < 2.3.1 | 2.3.1 |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qrw8-4f9g-c6gc: Memory leak in the OBJ_obj2txt function in LibreSSL before 2
ghsa_unreviewed·2022-05-24
CVE-2015-5333 [HIGH] CWE-400 GHSA-qrw8-4f9g-c6gc: Memory leak in the OBJ_obj2txt function in LibreSSL before 2
Memory leak in the OBJ_obj2txt function in LibreSSL before 2.3.1 allows remote attackers to cause a denial of service (memory consumption) via a large number of ASN.1 object identifiers in X.509 certificates.
Apple
CVE-2015-5333: macOS Mojave 10.14
vendor_apple·2018-09-24·CVSS 7.5
CVE-2015-5333 [HIGH] CVE-2015-5333: macOS Mojave 10.14
Apple Security Update: About the security content of macOS Mojave 10.14
Product: macOS Mojave
Version: 10.14
CVE: CVE-2015-5333
Component: CVE-2015-5333
Red Hat
flash-plugin: information leaks and hardening bypass fixed in APSB15-23
vendor_redhat·2015-09-21·CVSS 4.3
CVE-2015-5571 [MEDIUM] flash-plugin: information leaks and hardening bypass fixed in APSB15-23
flash-plugin: information leaks and hardening bypass fixed in APSB15-23
Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 do not properly restrict the SWF file format, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks against JSONP endpoints, and obtain sensitive information, via a crafted OBJECT element with SWF content satisfying the character-set requirements of a callback API. NOTE: this issue exists because of an incomplete fix for CVE-2014-4671 and CVE-2014-5333.
Red Hat
flash-plugin: cross-site request forgery against JSONP endpoints fixed in APSB15-11 (incomplete fix for CVE-2014-5333)
vendor_redhat·2015-06-09·CVSS 4.3
CVE-2015-3096 [MEDIUM] CWE-352 flash-plugin: cross-site request forgery against JSONP endpoints fixed in APSB15-11 (incomplete fix for CVE-2014-5333)
flash-plugin: cross-site request forgery against JSONP endpoints fixed in APSB15-11 (incomplete fix for CVE-2014-5333)
Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Windows and before 18.0.0.143 on OS X, and Adobe AIR SDK & Compiler before 18.0.0.144 on Windows and before 18.0.0.143 on OS X allow remote attackers to bypass a CVE-2014-5333 protection mechanism via unspecified vectors.
Apple
CVE-2015-5333: OS X El Capitan v10.11.4 and Security Update 2016-002
vendor_apple·CVSS 7.5
CVE-2015-5333 [HIGH] CVE-2015-5333: OS X El Capitan v10.11.4 and Security Update 2016-002
Apple Security Update: About the security content of OS X El Capitan v10.11.4 and Security Update 2016-002
Product: OS X El Capitan v10.11.4 and Security Update 2016-002
CVE: CVE-2015-5333
Component: CVE-ID
Apple
CVE-2015-5333: OS X El Capitan 10.11.2, Security Update 2015-005 Yosemite, and Security Update 2015-008 Mavericks
vendor_apple·CVSS 7.5
CVE-2015-5333 [HIGH] CVE-2015-5333: OS X El Capitan 10.11.2, Security Update 2015-005 Yosemite, and Security Update 2015-008 Mavericks
Apple Security Update: About the security content of OS X El Capitan 10.11.2, Security Update 2015-005 Yosemite, and Security Update 2015-008 Mavericks
Product: OS X El Capitan 10.11.2, Security Update 2015-005 Yosemite, and Security Update 2015-008 Mavericks
CVE: CVE-2015-5333
Component: CVE-2015-5333
No detection rules found.
No public exploits indexed.
http://ftp.openbsd.org/pub/OpenBSD/LibreSSL/libressl-2.3.1-relnotes.txthttp://lists.opensuse.org/opensuse-updates/2015-10/msg00050.htmlhttp://packetstormsecurity.com/files/133998/Qualys-Security-Advisory-LibreSSL-Leak-Overflow.htmlhttp://www.securityfocus.com/archive/1/archive/1/536692/100/0/threadedhttp://ftp.openbsd.org/pub/OpenBSD/LibreSSL/libressl-2.3.1-relnotes.txthttp://lists.opensuse.org/opensuse-updates/2015-10/msg00050.htmlhttp://packetstormsecurity.com/files/133998/Qualys-Security-Advisory-LibreSSL-Leak-Overflow.htmlhttp://www.securityfocus.com/archive/1/archive/1/536692/100/0/threaded
2020-01-23
Published