4.3

CVE-2015-0208

The ASN.1 signature-verification implementation in the rsa_item_verify function in crypto/rsa/rsa_ameth.c in OpenSSL 1.0.2 before 1.0.2a allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted RSA PSS parameters to an endpoint that uses the certificate-verification feature.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OpenSSLOpenSSL Version1.0.2
OpenSSLOpenSSL Version1.0.2 Updatebeta1
OpenSSLOpenSSL Version1.0.2 Updatebeta2
OpenSSLOpenSSL Version1.0.2 Updatebeta3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 23.76% 0.958
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P
http://marc.info/?l=bugtraq&m=144050155601375&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=143748090628601&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=144050297101809&w=2
Third Party Advisory
Mailing List
http://www.securitytracker.com/id/1031929
Third Party Advisory
VDB Entry
http://www.securityfocus.com/bid/73230
Third Party Advisory
VDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=1202369
Third Party Advisory
Issue Tracking