5.3

CVE-2015-3195

The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1q, and 1.0.2 before 1.0.2e mishandles errors caused by malformed X509_ATTRIBUTE data, which allows remote attackers to obtain sensitive information from process memory by triggering a decoding failure in a PKCS#7 or CMS application.

Data is provided by the National Vulnerability Database (NVD)
ApplemacOS X Version < 10.11.4
OracleApi Gateway Version11.1.2.3.0
OracleApi Gateway Version11.1.2.4.0
OracleHTTP Server Version11.5.10.2
OracleSun Ray Software Version11.1
OracleVm Server Version3.2 HwPlatformx86
OracleVm Virtualbox Version < 4.3.36
OracleVm Virtualbox Version >= 5.0.0 < 5.0.14
OracleIntegrated Lights Out Manager Firmware Version >= 3.0 <= 4.0.4
OracleLinux Version5 Update-
OracleLinux Version6 Update-
OracleLinux Version7 Update-
OracleSolaris Version10
OracleSolaris Version11.3
OpenSSLOpenSSL Version < 0.9.8zh
OpenSSLOpenSSL Version >= 1.0.0 < 1.0.0t
OpenSSLOpenSSL Version >= 1.0.1 < 1.0.1q
OpenSSLOpenSSL Version >= 1.0.2 < 1.0.2e
CanonicalUbuntu Linux Version12.04 SwEdition-
CanonicalUbuntu Linux Version14.04 SwEditionesm
CanonicalUbuntu Linux Version15.04
CanonicalUbuntu Linux Version15.10
DebianDebian Linux Version7.0
DebianDebian Linux Version8.0
OpensuseLeap Version42.1
OpensuseOpensuse Version11.4
OpensuseOpensuse Version13.1
OpensuseOpensuse Version13.2
SuseLinux Enterprise Server Version10 Updatesp4 SwEditionltss
FedoraprojectFedora Version22
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 3.48% 0.871
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

http://www.securityfocus.com/bid/91787
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1034294
Third Party Advisory
VDB Entry
http://marc.info/?l=bugtraq&m=145382583417444&w=2
Third Party Advisory
Mailing List
http://www.securityfocus.com/bid/78626
Third Party Advisory
VDB Entry