CVE
- Id
- 77552
- CVE No.
- CVE-2015-0289
- Status
- Candidate
- Description
- The PKCS#7 implementation in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a does not properly handle a lack of outer ContentInfo, which allows attackers to cause a denial of service (NULL pointer dereference and application crash) by leveraging an application that processes arbitrary PKCS#7 data and providing malformed data with ASN.1 encoding, related to crypto/pkcs7/pk7_doit.c and crypto/pkcs7/pk7_lib.c.
- Phase
- Assigned (20141118)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
709804 | 77552 | CVE-2015-0289 | CONFIRM:https://bugzilla.redhat.com/show_bug.cgi?id=1202384 | View |
709805 | 77552 | CVE-2015-0289 | CONFIRM:https://git.openssl.org/?p=openssl.git;a=commit;h=c0334c2c92dd1bc3ad8138ba6e74006c3631b0f9 | View |
709806 | 77552 | CVE-2015-0289 | CONFIRM:https://www.openssl.org/news/secadv_20150319.txt | View |
709807 | 77552 | CVE-2015-0289 | CONFIRM:https://access.redhat.com/articles/1384453 | View |
709808 | 77552 | CVE-2015-0289 | CONFIRM:http://support.apple.com/kb/HT204942 | View |
709809 | 77552 | CVE-2015-0289 | CONFIRM:http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html | View |
709810 | 77552 | CVE-2015-0289 | CONFIRM:http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html | View |
709811 | 77552 | CVE-2015-0289 | CONFIRM:https://bto.bluecoat.com/security-advisory/sa92 | View |
709812 | 77552 | CVE-2015-0289 | CONFIRM:http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html | View |
709813 | 77552 | CVE-2015-0289 | CONFIRM:http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.html | View |
709814 | 77552 | CVE-2015-0289 | CONFIRM:http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html | View |
709815 | 77552 | CVE-2015-0289 | CONFIRM:http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10680 | View |
709816 | 77552 | CVE-2015-0289 | CONFIRM:http://www.fortiguard.com/advisory/2015-03-24-openssl-vulnerabilities-march-2015 | View |
709817 | 77552 | CVE-2015-0289 | CONFIRM:https://kc.mcafee.com/corporate/index?page=content&id=SB10110 | View |
709818 | 77552 | CVE-2015-0289 | APPLE:APPLE-SA-2015-06-30-2 | View |
709819 | 77552 | CVE-2015-0289 | URL:http://lists.apple.com/archives/security-announce/2015/Jun/msg00002.html | View |
709820 | 77552 | CVE-2015-0289 | DEBIAN:DSA-3197 | View |
709821 | 77552 | CVE-2015-0289 | URL:http://www.debian.org/security/2015/dsa-3197 | View |
709822 | 77552 | CVE-2015-0289 | FEDORA:FEDORA-2015-4300 | View |
709823 | 77552 | CVE-2015-0289 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2015-March/152844.html | View |
709824 | 77552 | CVE-2015-0289 | FEDORA:FEDORA-2015-4303 | View |
709825 | 77552 | CVE-2015-0289 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2015-March/152733.html | View |
709826 | 77552 | CVE-2015-0289 | FEDORA:FEDORA-2015-4320 | View |
709827 | 77552 | CVE-2015-0289 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2015-March/152734.html | View |
709828 | 77552 | CVE-2015-0289 | FEDORA:FEDORA-2015-6855 | View |
709829 | 77552 | CVE-2015-0289 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157177.html | View |
709830 | 77552 | CVE-2015-0289 | FEDORA:FEDORA-2015-6951 | View |
709831 | 77552 | CVE-2015-0289 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2015-May/156823.html | View |
709832 | 77552 | CVE-2015-0289 | FREEBSD:FreeBSD-SA-15:06 | View |
709833 | 77552 | CVE-2015-0289 | URL:https://www.freebsd.org/security/advisories/FreeBSD-SA-15%3A06.openssl.asc | View |
709834 | 77552 | CVE-2015-0289 | GENTOO:GLSA-201503-11 | View |
709835 | 77552 | CVE-2015-0289 | URL:https://security.gentoo.org/glsa/201503-11 | View |
709836 | 77552 | CVE-2015-0289 | HP:HPSBGN03306 | View |
709837 | 77552 | CVE-2015-0289 | URL:http://marc.info/?l=bugtraq&m=142841429220765&w=2 | View |
709838 | 77552 | CVE-2015-0289 | HP:HPSBMU03380 | View |
709839 | 77552 | CVE-2015-0289 | URL:http://marc.info/?l=bugtraq&m=143748090628601&w=2 | View |
709840 | 77552 | CVE-2015-0289 | HP:HPSBMU03397 | View |
709841 | 77552 | CVE-2015-0289 | URL:http://marc.info/?l=bugtraq&m=144050297101809&w=2 | View |
709842 | 77552 | CVE-2015-0289 | HP:HPSBMU03409 | View |
709843 | 77552 | CVE-2015-0289 | URL:http://marc.info/?l=bugtraq&m=144050155601375&w=2 | View |
709844 | 77552 | CVE-2015-0289 | HP:HPSBUX03334 | View |
709845 | 77552 | CVE-2015-0289 | URL:http://marc.info/?l=bugtraq&m=143213830203296&w=2 | View |
709846 | 77552 | CVE-2015-0289 | HP:SSRT102000 | View |
709847 | 77552 | CVE-2015-0289 | URL:http://marc.info/?l=bugtraq&m=143213830203296&w=2 | View |
709848 | 77552 | CVE-2015-0289 | MANDRIVA:MDVSA-2015:062 | View |
709849 | 77552 | CVE-2015-0289 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2015:062 | View |
709850 | 77552 | CVE-2015-0289 | MANDRIVA:MDVSA-2015:063 | View |
709851 | 77552 | CVE-2015-0289 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2015:063 | View |
709852 | 77552 | CVE-2015-0289 | REDHAT:RHSA-2015:0716 | View |
709853 | 77552 | CVE-2015-0289 | URL:http://rhn.redhat.com/errata/RHSA-2015-0716.html | View |
709854 | 77552 | CVE-2015-0289 | REDHAT:RHSA-2015:0715 | View |
709855 | 77552 | CVE-2015-0289 | URL:http://rhn.redhat.com/errata/RHSA-2015-0715.html | View |
709856 | 77552 | CVE-2015-0289 | REDHAT:RHSA-2015:0752 | View |
709857 | 77552 | CVE-2015-0289 | URL:http://rhn.redhat.com/errata/RHSA-2015-0752.html | View |
709858 | 77552 | CVE-2015-0289 | REDHAT:RHSA-2015:0800 | View |
709859 | 77552 | CVE-2015-0289 | URL:http://rhn.redhat.com/errata/RHSA-2015-0800.html | View |
709860 | 77552 | CVE-2015-0289 | SUSE:openSUSE-SU-2015:0554 | View |
709861 | 77552 | CVE-2015-0289 | URL:http://lists.opensuse.org/opensuse-updates/2015-03/msg00062.html | View |
709862 | 77552 | CVE-2015-0289 | SUSE:SUSE-SU-2015:0541 | View |
709863 | 77552 | CVE-2015-0289 | URL:http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00022.html | View |
709864 | 77552 | CVE-2015-0289 | SUSE:SUSE-SU-2015:0578 | View |
709865 | 77552 | CVE-2015-0289 | URL:http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00027.html | View |
709866 | 77552 | CVE-2015-0289 | SUSE:openSUSE-SU-2016:0640 | View |
709867 | 77552 | CVE-2015-0289 | URL:http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.html | View |
709868 | 77552 | CVE-2015-0289 | SUSE:openSUSE-SU-2015:1277 | View |
709869 | 77552 | CVE-2015-0289 | URL:http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00037.html | View |
709870 | 77552 | CVE-2015-0289 | UBUNTU:USN-2537-1 | View |
709871 | 77552 | CVE-2015-0289 | URL:http://www.ubuntu.com/usn/USN-2537-1 | View |
709872 | 77552 | CVE-2015-0289 | BID:73231 | View |
709873 | 77552 | CVE-2015-0289 | URL:http://www.securityfocus.com/bid/73231 | View |
709874 | 77552 | CVE-2015-0289 | SECTRACK:1031929 | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
6493 | JVNDB-2015-001813 | Adobe Flash Player における任意のコードを実行される脆弱性 | Adobe Flash Player には、解放済みメモリの使用 (Use-after-free) により、任意のコードを実行される脆弱性が存在します。 | CVE-2015-0341 | 77552 | 10 | http://jvndb.jvn.jp/ja/contents/2015/JVNDB-2015-001813.html | View |