CVE Database
/

CVE-2015-5334

Back to search

CVE-2015-5334

Published: Jan 23, 2020

Modified: Aug 6, 2024

PUBLISHED

Description

Off-by-one error in the OBJ_obj2txt function in LibreSSL before 2.3.1 allows remote attackers to cause a denial of service (program crash) or possible execute arbitrary code via a crafted X.509 certificate, which triggers a stack-based buffer overflow. Note: this vulnerability exists because of an incorrect fix for CVE-2014-3508.

VendorProductVersions

LibreSSL

LibreSSL

affected
before 2.3.1

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now