NVD
- Id
- 24032
- Name
- CVE-2015-1792
- Description
- The do_free_upto function in crypto/cms/cms_smime.c in OpenSSL before 0.9.8zg, 1.0.0 before 1.0.0s, 1.0.1 before 1.0.1n, and 1.0.2 before 1.0.2b allows remote attackers to cause a denial of service (infinite loop) via vectors that trigger a NULL value of a BIO data structure, as demonstrated by an unrecognized X.660 OID for a hash function.
- Reject
- CVSS Version
- 2
- CVSS Score
- 5
- Severity
- Medium
- CVSS Base Score
- 5
- CVSS Impact Subscore
- 2.9
- CVSS Exploit Subscore
- 10
- CVSS Vector
- (AV:N/AC:L/Au:N/C:N/I:N/A:P)
- Pub Date
- 2017-01-19
- Published
- 2015-06-12
- Modified Date
- 2016-12-30
- Seq
- 2015-1792
Related NVD References
| Id | NVD Id | NVD No. | Reference | Actions |
|---|---|---|---|---|
| 127416 | 24032 | CVE-2015-1792 | http://fortiguard.com/advisory/openssl-vulnerabilities-june-2015 | View |
| 127417 | 24032 | CVE-2015-1792 | NetBSD-SA2015-008 | View |
| 127418 | 24032 | CVE-2015-1792 | http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10694 | View |
| 127419 | 24032 | CVE-2015-1792 | APPLE-SA-2015-08-13-2 | View |
| 127420 | 24032 | CVE-2015-1792 | FEDORA-2015-10047 | View |
| 127421 | 24032 | CVE-2015-1792 | FEDORA-2015-10108 | View |
| 127422 | 24032 | CVE-2015-1792 | openSUSE-SU-2015:1139 | View |
| 127423 | 24032 | CVE-2015-1792 | SUSE-SU-2015:1143 | View |
| 127424 | 24032 | CVE-2015-1792 | SUSE-SU-2015:1150 | View |
| 127425 | 24032 | CVE-2015-1792 | SUSE-SU-2015:1182 | View |
| 127426 | 24032 | CVE-2015-1792 | SUSE-SU-2015:1184 | View |
| 127427 | 24032 | CVE-2015-1792 | SUSE-SU-2015:1185 | View |
| 127428 | 24032 | CVE-2015-1792 | openSUSE-SU-2015:1277 | View |
| 127429 | 24032 | CVE-2015-1792 | openSUSE-SU-2016:0640 | View |
| 127430 | 24032 | CVE-2015-1792 | HPSBGN03371 | View |
| 127431 | 24032 | CVE-2015-1792 | SSRT102180 | View |
| 127432 | 24032 | CVE-2015-1792 | HPSBMU03409 | View |
| 127433 | 24032 | CVE-2015-1792 | RHSA-2015:1115 | View |
| 127434 | 24032 | CVE-2015-1792 | 20150612 Multiple Vulnerabilities in OpenSSL (June 2015) Affecting Cisco Products | View |
| 127435 | 24032 | CVE-2015-1792 | DSA-3287 | View |
| 127436 | 24032 | CVE-2015-1792 | http://www.fortiguard.com/advisory/2015-06-11-fortinet-vulnerability-openssl-vulnerabilities-june-2015 | View |
| 127437 | 24032 | CVE-2015-1792 | http://www.fortiguard.com/advisory/openssl-vulnerabilities-june-2015 | View |
| 127438 | 24032 | CVE-2015-1792 | http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html | View |
| 127439 | 24032 | CVE-2015-1792 | http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html | View |
| 127440 | 24032 | CVE-2015-1792 | http://www.oracle.com/technetwork/topics/security/bulletinjul2015-2511963.html | View |
| 127441 | 24032 | CVE-2015-1792 | http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html | View |
| 127442 | 24032 | CVE-2015-1792 | http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html | View |
| 127443 | 24032 | CVE-2015-1792 | 75154 | View |
| 127444 | 24032 | CVE-2015-1792 | 91787 | View |
| 127445 | 24032 | CVE-2015-1792 | 1032564 | View |
| 127446 | 24032 | CVE-2015-1792 | USN-2639-1 | View |
| 127447 | 24032 | CVE-2015-1792 | https://bto.bluecoat.com/security-advisory/sa98 | View |
| 127448 | 24032 | CVE-2015-1792 | https://github.com/openssl/openssl/commit/cd30f03ac5bf2962f44bd02ae8d88245dff2f12c | View |
| 127449 | 24032 | CVE-2015-1792 | https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05045763 | View |
| 127450 | 24032 | CVE-2015-1792 | https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05131044 | View |
| 127451 | 24032 | CVE-2015-1792 | https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05150888 | View |
| 127452 | 24032 | CVE-2015-1792 | https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05158380 | View |
| 127453 | 24032 | CVE-2015-1792 | https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05184351 | View |
| 127454 | 24032 | CVE-2015-1792 | https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05353965 | View |
| 127455 | 24032 | CVE-2015-1792 | https://kc.mcafee.com/corporate/index?page=content&id=SB10122 | View |
| 127456 | 24032 | CVE-2015-1792 | https://openssl.org/news/secadv/20150611.txt | View |
| 127457 | 24032 | CVE-2015-1792 | GLSA-201506-02 | View |
| 127458 | 24032 | CVE-2015-1792 | https://support.apple.com/kb/HT205031 | View |
| 127459 | 24032 | CVE-2015-1792 | https://www.openssl.org/news/secadv_20150611.txt | View |
Related JVN
| Id | Name | Title | Summary | Cveinfo Name | Cveinfo Id | Nvdinfo Name | Nvdinfo Id | Cvssv2 | Cvssv3 | Jvnurl | Published Date | Last Updated Date | Actions |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 7764 | JVNDB-2015-003084 | OpenSSL の crypto/cms/cms_smime.c の do_free_upto 関数におけるサービス運用妨害 (DoS) の脆弱性 | OpenSSL の crypto/cms/cms_smime.c の do_free_upto 関数には、サービス運用妨害 (無限ループ) 状態にされる脆弱性が存在します。 | CVE-2015-1792 | 79017 | CVE-2015-1792 | 24032 | 5 | http://jvndb.jvn.jp/ja/contents/2015/JVNDB-2015-003084.html | 2015-06-11 | 2016-10-07 | View |