The ASN1_TYPE_cmp function in crypto/asn1/a_type.c in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a does not properly perform boolean-type comparisons, which allows remote attackers to cause a denial of service (invalid read operation and application crash) via a crafted X.509 certificate to an endpoint that uses the certificate-verification feature.

Subscriptions

Vendors Products
Openssl Subscribe
Openssl Subscribe
Enterprise Linux Subscribe
Jboss Core Services Subscribe
Storage Subscribe

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-177-1 openssl security update
Debian DSA Debian DSA DSA-3197-1 openssl security update
Debian DSA Debian DSA DSA-3197-2 openssl regression update
Ubuntu USN Ubuntu USN USN-2537-1 OpenSSL vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10680 cve-icon cve-icon
http://lists.apple.com/archives/security-announce/2015/Jun/msg00002.html cve-icon cve-icon
http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html cve-icon cve-icon
http://lists.apple.com/archives/security-announce/2015/Sep/msg00008.html cve-icon cve-icon
http://lists.fedoraproject.org/pipermail/package-announce/2015-March/152733.html cve-icon cve-icon
http://lists.fedoraproject.org/pipermail/package-announce/2015-March/152734.html cve-icon cve-icon
http://lists.fedoraproject.org/pipermail/package-announce/2015-March/152844.html cve-icon cve-icon
http://lists.fedoraproject.org/pipermail/package-announce/2015-May/156823.html cve-icon cve-icon
http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157177.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00022.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00027.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00037.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-updates/2015-03/msg00062.html cve-icon cve-icon
http://marc.info/?l=bugtraq&m=142841429220765&w=2 cve-icon cve-icon
http://marc.info/?l=bugtraq&m=143213830203296&w=2 cve-icon cve-icon
http://marc.info/?l=bugtraq&m=143748090628601&w=2 cve-icon cve-icon
http://marc.info/?l=bugtraq&m=144050155601375&w=2 cve-icon cve-icon
http://marc.info/?l=bugtraq&m=144050254401665&w=2 cve-icon cve-icon
http://marc.info/?l=bugtraq&m=144050297101809&w=2 cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2015-0715.html cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2015-0716.html cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2015-0752.html cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2016-2957.html cve-icon cve-icon
http://support.apple.com/kb/HT204942 cve-icon cve-icon
http://www.debian.org/security/2015/dsa-3197 cve-icon cve-icon
http://www.fortiguard.com/advisory/2015-03-24-openssl-vulnerabilities-march-2015 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDVSA-2015:062 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDVSA-2015:063 cve-icon cve-icon
http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html cve-icon cve-icon
http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html cve-icon cve-icon
http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html cve-icon cve-icon
http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.html cve-icon cve-icon
http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html cve-icon cve-icon
http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html cve-icon cve-icon
http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html cve-icon cve-icon
http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html cve-icon cve-icon
http://www.securityfocus.com/bid/73225 cve-icon cve-icon
http://www.securitytracker.com/id/1031929 cve-icon cve-icon
http://www.securitytracker.com/id/1032917 cve-icon cve-icon
http://www.ubuntu.com/usn/USN-2537-1 cve-icon cve-icon
https://access.redhat.com/articles/1384453 cve-icon cve-icon cve-icon
https://bto.bluecoat.com/security-advisory/sa92 cve-icon cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=1202366 cve-icon cve-icon
https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdf cve-icon cve-icon
https://git.openssl.org/?p=openssl.git%3Ba=commit%3Bh=c3c7fb07dc975dc3c9de0eddb7d8fd79fc9c67c1 cve-icon cve-icon
https://kc.mcafee.com/corporate/index?page=content&id=SB10110 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2015-0286 cve-icon
https://openssl.org/news/secadv_20150319.txt cve-icon
https://support.apple.com/HT205212 cve-icon cve-icon
https://support.apple.com/HT205267 cve-icon cve-icon
https://support.citrix.com/article/CTX216642 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2015-0286 cve-icon
https://www.freebsd.org/security/advisories/FreeBSD-SA-15%3A06.openssl.asc cve-icon cve-icon
https://www.openssl.org/news/secadv_20150319.txt cve-icon cve-icon
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-06T04:03:10.760Z

Reserved: 2014-11-18T00:00:00.000Z

Link: CVE-2015-0286

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2015-03-19T22:59:04.677

Modified: 2025-04-12T10:46:40.837

Link: CVE-2015-0286

cve-icon Redhat

Severity : Moderate

Publid Date: 2015-03-19T00:00:00Z

Links: CVE-2015-0286 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses