The ASN1_item_ex_d2i function in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a does not reinitialize CHOICE and ADB data structures, which might allow attackers to cause a denial of service (invalid write operation and memory corruption) by leveraging an application that relies on ASN.1 structure reuse.

Project Subscriptions

Vendors Products
Openssl Subscribe
Openssl Subscribe
Enterprise Linux Subscribe
Storage Subscribe
Advisories
Source ID Title
Debian DLA Debian DLA DLA-177-1 openssl security update
Debian DSA Debian DSA DSA-3197-1 openssl security update
Debian DSA Debian DSA DSA-3197-2 openssl regression update
EUVD EUVD EUVD-2015-0300 The ASN1_item_ex_d2i function in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a does not reinitialize CHOICE and ADB data structures, which might allow attackers to cause a denial of service (invalid write operation and memory corruption) by leveraging an application that relies on ASN.1 structure reuse.
Ubuntu USN Ubuntu USN USN-2537-1 OpenSSL vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10680 cve-icon cve-icon
http://lists.apple.com/archives/security-announce/2015/Jun/msg00002.html cve-icon cve-icon
http://lists.apple.com/archives/security-announce/2015/Sep/msg00001.html cve-icon cve-icon
http://lists.apple.com/archives/security-announce/2015/Sep/msg00008.html cve-icon cve-icon
http://lists.fedoraproject.org/pipermail/package-announce/2015-March/152733.html cve-icon cve-icon
http://lists.fedoraproject.org/pipermail/package-announce/2015-March/152734.html cve-icon cve-icon
http://lists.fedoraproject.org/pipermail/package-announce/2015-March/152844.html cve-icon cve-icon
http://lists.fedoraproject.org/pipermail/package-announce/2015-May/156823.html cve-icon cve-icon
http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157177.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00022.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00027.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00037.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00017.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-updates/2015-03/msg00062.html cve-icon cve-icon
http://marc.info/?l=bugtraq&m=142841429220765&w=2 cve-icon cve-icon
http://marc.info/?l=bugtraq&m=143213830203296&w=2 cve-icon cve-icon
http://marc.info/?l=bugtraq&m=143748090628601&w=2 cve-icon cve-icon
http://marc.info/?l=bugtraq&m=144050155601375&w=2 cve-icon cve-icon
http://marc.info/?l=bugtraq&m=144050297101809&w=2 cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2015-0715.html cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2015-0716.html cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2015-0752.html cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2015-0800.html cve-icon cve-icon
http://support.apple.com/kb/HT204942 cve-icon cve-icon
http://www.debian.org/security/2015/dsa-3197 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDVSA-2015:062 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDVSA-2015:063 cve-icon cve-icon
http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html cve-icon cve-icon
http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.html cve-icon cve-icon
http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html cve-icon cve-icon
http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html cve-icon cve-icon
http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html cve-icon cve-icon
http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html cve-icon cve-icon
http://www.securityfocus.com/bid/73227 cve-icon cve-icon
http://www.securitytracker.com/id/1031929 cve-icon cve-icon
http://www.ubuntu.com/usn/USN-2537-1 cve-icon cve-icon
https://access.redhat.com/articles/1384453 cve-icon cve-icon cve-icon
https://bto.bluecoat.com/security-advisory/sa92 cve-icon cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=1202380 cve-icon cve-icon
https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdf cve-icon cve-icon
https://git.openssl.org/?p=openssl.git%3Ba=commit%3Bh=b717b083073b6cacc0a5e2397b661678aff7ae7f cve-icon cve-icon
https://kc.mcafee.com/corporate/index?page=content&id=SB10110 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2015-0287 cve-icon
https://openssl.org/news/secadv_20150319.txt cve-icon
https://security.gentoo.org/glsa/201503-11 cve-icon cve-icon
https://support.apple.com/HT205212 cve-icon cve-icon
https://support.apple.com/HT205267 cve-icon cve-icon
https://support.citrix.com/article/CTX216642 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2015-0287 cve-icon
https://www.freebsd.org/security/advisories/FreeBSD-SA-15%3A06.openssl.asc cve-icon cve-icon
https://www.openssl.org/news/secadv_20150319.txt cve-icon cve-icon
History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-06T04:03:10.946Z

Reserved: 2014-11-18T00:00:00

Link: CVE-2015-0287

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2015-03-19T22:59:05.770

Modified: 2025-04-12T10:46:40.837

Link: CVE-2015-0287

cve-icon Redhat

Severity : Low

Publid Date: 2015-03-19T00:00:00Z

Links: CVE-2015-0287 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses