CVE Database
/

CVE-2015-3194

Back to search

CVE-2015-3194

Published: Dec 6, 2015

Modified: Aug 6, 2024

PUBLISHED

Description

crypto/rsa/rsa_ameth.c in OpenSSL 1.0.1 before 1.0.1q and 1.0.2 before 1.0.2e allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an RSA PSS ASN.1 signature that lacks a mask generation function parameter.

VendorProductVersions

n/a

n/a

affected
n/a

References

78623
vdb-entry
openSUSE-SU-2016:1332
vendor-advisory
openSUSE-SU-2015:2288
vendor-advisory
RHSA-2015:2617
vendor-advisory
SSA:2015-349-04
vendor-advisory
HPSBGN03536
vendor-advisory
USN-2830-1
vendor-advisory
openSUSE-SU-2015:2289
vendor-advisory
FEDORA-2015-d87d60b9a9
vendor-advisory
91787
vdb-entry
RHSA-2016:2957
vendor-advisory
1034294
vdb-entry
openSUSE-SU-2016:0637
vendor-advisory
DSA-3413
vendor-advisory
openSUSE-SU-2015:2318
vendor-advisory

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now