Vulnerability CVE-2015-0287: Information

Description

The ASN1_item_ex_d2i function in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a does not reinitialize CHOICE and ADB data structures, which might allow attackers to cause a denial of service (invalid write operation and memory corruption) by leveraging an application that relies on ASN.1 structure reuse.

Severity: MEDIUM (5.0)

Published: March 20, 2015
Modified: Nov. 7, 2023
Error type identifier: CWE-17

Fixed packages

References to Advisories, Solutions, and Tools

Hyperlink
Resource
https://www.openssl.org/news/secadv_20150319.txt
  • Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1202380
    FEDORA-2015-4300
      FEDORA-2015-4303
        FEDORA-2015-4320
          DSA-3197
            openSUSE-SU-2015:0554
              FreeBSD-SA-15:06
                SUSE-SU-2015:0541
                  USN-2537-1
                    1031929
                      SUSE-SU-2015:0578
                        RHSA-2015:0716
                          MDVSA-2015:063
                            MDVSA-2015:062
                              RHSA-2015:0752
                                RHSA-2015:0715
                                  HPSBGN03306
                                    RHSA-2015:0800
                                      https://access.redhat.com/articles/1384453
                                        FEDORA-2015-6951
                                          FEDORA-2015-6855
                                            APPLE-SA-2015-06-30-2
                                              http://support.apple.com/kb/HT204942
                                                http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html
                                                  https://support.apple.com/HT205212
                                                    APPLE-SA-2015-09-16-1
                                                      https://support.apple.com/HT205267
                                                        APPLE-SA-2015-09-30-3
                                                          http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html
                                                            https://bto.bluecoat.com/security-advisory/sa92
                                                              http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html
                                                                HPSBMU03397
                                                                  SSRT102000
                                                                    HPSBMU03380
                                                                      HPSBMU03409
                                                                        http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.html
                                                                          http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html
                                                                            SUSE-SU-2016:0678
                                                                              openSUSE-SU-2016:0640
                                                                                GLSA-201503-11
                                                                                  http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10680
                                                                                    openSUSE-SU-2015:1277
                                                                                      https://kc.mcafee.com/corporate/index?page=content&id=SB10110
                                                                                        73227
                                                                                          http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
                                                                                            https://support.citrix.com/article/CTX216642
                                                                                              https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdf
                                                                                                https://git.openssl.org/?p=openssl.git%3Ba=commit%3Bh=b717b083073b6cacc0a5e2397b661678aff7ae7f
                                                                                                    1. Configuration 1

                                                                                                      cpe:2.3:a:openssl:openssl:1.0.1j:*:*:*:*:*:*:*

                                                                                                      cpe:2.3:a:openssl:openssl:1.0.0n:*:*:*:*:*:*:*

                                                                                                      cpe:2.3:a:openssl:openssl:1.0.0c:*:*:*:*:*:*:*

                                                                                                      cpe:2.3:a:openssl:openssl:1.0.0i:*:*:*:*:*:*:*

                                                                                                      cpe:2.3:a:openssl:openssl:1.0.1h:*:*:*:*:*:*:*

                                                                                                      cpe:2.3:a:openssl:openssl:1.0.0m:*:*:*:*:*:*:*

                                                                                                      cpe:2.3:a:openssl:openssl:1.0.1c:*:*:*:*:*:*:*

                                                                                                      cpe:2.3:a:openssl:openssl:1.0.1g:*:*:*:*:*:*:*

                                                                                                      cpe:2.3:a:openssl:openssl:1.0.0h:*:*:*:*:*:*:*

                                                                                                      cpe:2.3:a:openssl:openssl:1.0.0e:*:*:*:*:*:*:*

                                                                                                      cpe:2.3:a:openssl:openssl:1.0.0f:*:*:*:*:*:*:*

                                                                                                      cpe:2.3:a:openssl:openssl:1.0.0d:*:*:*:*:*:*:*

                                                                                                      cpe:2.3:a:openssl:openssl:1.0.0j:*:*:*:*:*:*:*

                                                                                                      cpe:2.3:a:openssl:openssl:1.0.0p:*:*:*:*:*:*:*

                                                                                                      cpe:2.3:a:openssl:openssl:1.0.1a:*:*:*:*:*:*:*

                                                                                                      cpe:2.3:a:openssl:openssl:1.0.0o:*:*:*:*:*:*:*

                                                                                                      cpe:2.3:a:openssl:openssl:1.0.1d:*:*:*:*:*:*:*

                                                                                                      cpe:2.3:a:openssl:openssl:1.0.0k:*:*:*:*:*:*:*

                                                                                                      cpe:2.3:a:openssl:openssl:1.0.1k:*:*:*:*:*:*:*

                                                                                                      cpe:2.3:a:openssl:openssl:1.0.0:*:*:*:*:*:*:*

                                                                                                      cpe:2.3:a:openssl:openssl:1.0.1b:*:*:*:*:*:*:*

                                                                                                      cpe:2.3:a:openssl:openssl:1.0.1e:*:*:*:*:*:*:*

                                                                                                      cpe:2.3:a:openssl:openssl:1.0.1l:*:*:*:*:*:*:*

                                                                                                      cpe:2.3:a:openssl:openssl:1.0.1f:*:*:*:*:*:*:*

                                                                                                      cpe:2.3:a:openssl:openssl:1.0.0l:*:*:*:*:*:*:*

                                                                                                      cpe:2.3:a:openssl:openssl:1.0.2:*:*:*:*:*:*:*

                                                                                                      cpe:2.3:a:openssl:openssl:1.0.0a:*:*:*:*:*:*:*

                                                                                                      cpe:2.3:a:openssl:openssl:1.0.0q:*:*:*:*:*:*:*

                                                                                                      cpe:2.3:a:openssl:openssl:1.0.1i:*:*:*:*:*:*:*

                                                                                                      cpe:2.3:a:openssl:openssl:1.0.0b:*:*:*:*:*:*:*

                                                                                                      cpe:2.3:a:openssl:openssl:1.0.1:*:*:*:*:*:*:*

                                                                                                      cpe:2.3:a:openssl:openssl:1.0.0g:*:*:*:*:*:*:*

                                                                                                      cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
                                                                                                      End including
                                                                                                      0.9.8ze