CVE-2015-5334
published 2020-01-23CVE-2015-5334: Off-by-one error in the OBJ_obj2txt function in LibreSSL before 2.3.1 allows remote attackers to cause a denial of service (program crash) or possible execute…
PriorityP351critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
3.49%
87.8th percentile
Off-by-one error in the OBJ_obj2txt function in LibreSSL before 2.3.1 allows remote attackers to cause a denial of service (program crash) or possible execute arbitrary code via a crafted X.509 certificate, which triggers a stack-based buffer overflow. Note: this vulnerability exists because of an incorrect fix for CVE-2014-3508.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos_mojave | — | — |
| apple | os_x_el_capitan_10.11.2_security_update_2015-005_yosemite_and_security_update_20 | — | — |
| apple | os_x_el_capitan_v10.11.4_and_security_update_2016-002 | — | — |
| openbsd | libressl | < 2.3.1 | 2.3.1 |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6q9j-c3rh-x87m: Off-by-one error in the OBJ_obj2txt function in LibreSSL before 2
ghsa_unreviewed·2022-05-24·CVSS 4.3
CVE-2015-5334 [MEDIUM] GHSA-6q9j-c3rh-x87m: Off-by-one error in the OBJ_obj2txt function in LibreSSL before 2
Off-by-one error in the OBJ_obj2txt function in LibreSSL before 2.3.1 allows remote attackers to cause a denial of service (program crash) or possible execute arbitrary code via a crafted X.509 certificate, which triggers a stack-based buffer overflow. Note: this vulnerability exists because of an incorrect fix for CVE-2014-3508.
Apple
CVE-2015-5334: macOS Mojave 10.14
vendor_apple·2018-09-24·CVSS 9.8
CVE-2015-5334 [CRITICAL] CVE-2015-5334: macOS Mojave 10.14
Apple Security Update: About the security content of macOS Mojave 10.14
Product: macOS Mojave
Version: 10.14
CVE: CVE-2015-5334
Component: CVE-2015-5334
Apple
CVE-2015-5334: OS X El Capitan v10.11.4 and Security Update 2016-002
vendor_apple·CVSS 9.8
CVE-2015-5334 [CRITICAL] CVE-2015-5334: OS X El Capitan v10.11.4 and Security Update 2016-002
Apple Security Update: About the security content of OS X El Capitan v10.11.4 and Security Update 2016-002
Product: OS X El Capitan v10.11.4 and Security Update 2016-002
CVE: CVE-2015-5334
Component: CVE-ID
Apple
CVE-2015-5334: OS X El Capitan 10.11.2, Security Update 2015-005 Yosemite, and Security Update 2015-008 Mavericks
vendor_apple·CVSS 9.8
CVE-2015-5334 [CRITICAL] CVE-2015-5334: OS X El Capitan 10.11.2, Security Update 2015-005 Yosemite, and Security Update 2015-008 Mavericks
Apple Security Update: About the security content of OS X El Capitan 10.11.2, Security Update 2015-005 Yosemite, and Security Update 2015-008 Mavericks
Product: OS X El Capitan 10.11.2, Security Update 2015-005 Yosemite, and Security Update 2015-008 Mavericks
CVE: CVE-2015-5334
Component: CVE-2015-5334
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://ftp.openbsd.org/pub/OpenBSD/LibreSSL/libressl-2.3.1-relnotes.txthttp://lists.opensuse.org/opensuse-updates/2015-10/msg00050.htmlhttp://packetstormsecurity.com/files/133998/Qualys-Security-Advisory-LibreSSL-Leak-Overflow.htmlhttp://seclists.org/fulldisclosure/2015/Oct/75http://www.securityfocus.com/archive/1/archive/1/536692/100/0/threadedhttp://ftp.openbsd.org/pub/OpenBSD/LibreSSL/libressl-2.3.1-relnotes.txthttp://lists.opensuse.org/opensuse-updates/2015-10/msg00050.htmlhttp://packetstormsecurity.com/files/133998/Qualys-Security-Advisory-LibreSSL-Leak-Overflow.htmlhttp://seclists.org/fulldisclosure/2015/Oct/75http://www.securityfocus.com/archive/1/archive/1/536692/100/0/threaded
2020-01-23
Published