Back to search
CVE-2015-3195
Published: Dec 6, 2015
Modified: Aug 6, 2024
PUBLISHED
Description
The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1q, and 1.0.2 before 1.0.2e mishandles errors caused by malformed X509_ATTRIBUTE data, which allows remote attackers to obtain sensitive information from process memory by triggering a decoding failure in a PKCS#7 or CMS application.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
APPLE-SA-2016-03-21-5
vendor-advisory
RHSA-2016:2056
vendor-advisory
openSUSE-SU-2015:2288
vendor-advisory
RHSA-2015:2617
vendor-advisory
SSA:2015-349-04
vendor-advisory
openSUSE-SU-2016:0640
vendor-advisory
78626
vdb-entry
RHSA-2015:2616
vendor-advisory
HPSBGN03536
vendor-advisory
USN-2830-1
vendor-advisory
openSUSE-SU-2015:2289
vendor-advisory
FEDORA-2015-d87d60b9a9
vendor-advisory
91787
vdb-entry
RHSA-2016:2957
vendor-advisory
1034294
vdb-entry
SUSE-SU-2016:0678
vendor-advisory
openSUSE-SU-2016:0637
vendor-advisory
DSA-3413
vendor-advisory
openSUSE-SU-2015:2318
vendor-advisory
openSUSE-SU-2015:2349
vendor-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now