MEDIUM · 5.3

CVE-2015-3195

The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1q, and 1.0.2 before 1.0.2e mishandles errors caused by malformed X509_A...

Vulnerability Description

The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1q, and 1.0.2 before 1.0.2e mishandles errors caused by malformed X509_ATTRIBUTE data, which allows remote attackers to obtain sensitive information from process memory by triggering a decoding failure in a PKCS#7 or CMS application.

CVSS Score

5.3

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
LOW

Affected Products

VendorProductVersions
AppleMac Os X< 10.11.4
OracleApi Gateway11.1.2.3.0
OracleCommunications Webrtc Session Controller7.0
OracleExalogic Infrastructure1.0
OracleHttp Server11.5.10.2
OracleLife Sciences Data Hub2.1
OracleSun Ray Software11.1
OracleTransportation Management6.1
OracleVm Server3.2
OracleVm Virtualbox< 4.3.36
OracleIntegrated Lights Out Manager Firmware>= 3.0, <= 4.0.4
OracleLinux5
OracleSolaris10
OpensslOpenssl< 0.9.8zh
RedhatEnterprise Linux Desktop5.0
RedhatEnterprise Linux Server5.0
RedhatEnterprise Linux Server Aus7.2
RedhatEnterprise Linux Server Tus7.2
RedhatEnterprise Linux Workstation5.0
CanonicalUbuntu Linux12.04

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-3195?

CVE-2015-3195 is a vulnerability with a CVSS score of 5.3 (MEDIUM). The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1q, and 1.0.2 before 1.0.2e mishandles errors caused by malformed X509_A...

How severe is CVE-2015-3195?

CVE-2015-3195 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-3195?

Check the references section above for vendor advisories and patch information. Affected products include: Apple Mac Os X, Oracle Api Gateway, Oracle Communications Webrtc Session Controller, Oracle Exalogic Infrastructure, Oracle Http Server.