NULL pointer dereference in OpenSSL - CVE-2015-3194
Published: June 20, 2023
Vulnerability identifier: #VU77550
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-3194
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error in crypto/rsa/rsa_ameth.c in OpenSSL. A remote attacker can trigger denial of service conditions via an RSA PSS ASN.1 signature that lacks a mask generation function parameter.
Affected software
OpenSSL
FlashSystem 840 9840-AE1 & 9843-AE1
SnapDrive for Unix
SnapDrive for Windows
Integrated Management Module II (IMM2)
Fedora
Slackware Linux
openssl
openssl-solibs
openssl101e
FlashSystem 900 9840-AE2 and 9843-AE2
FOS Firmware
IBM BladeCenter Advanced Management Module
IBM Cloud Pak for Business Automation
FlashSystem 840 9840-AE1 & 9843-AE1
SnapDrive for Unix
SnapDrive for Windows
Integrated Management Module II (IMM2)
Fedora
Slackware Linux
openssl
openssl-solibs
openssl101e
FlashSystem 900 9840-AE2 and 9843-AE2
FOS Firmware
IBM BladeCenter Advanced Management Module
IBM Cloud Pak for Business Automation
How to mitigate CVE-2015-3194
Cybersecurity Help is currently unaware of any official solution to address this vulnerability..
OpenSSL - update to 1.0.1q
SnapDrive for Unix - update to 5.3.1
SnapDrive for Windows - update to 7.1.4
openssl - addressed in versions 0.9.8zh, 1.0.1q
openssl-solibs - addressed in versions 0.9.8zh, 1.0.1q
Integrated Management Module II (IMM2) - update to 1aoo72h-5.60
openssl101e - update to 1.0.1e-5.el5
openssl - addressed in versions 1.0.1k-13.fc22, 1.0.2e-1.fc23
FlashSystem 900 9840-AE2 and 9843-AE2 - addressed in versions 1.2.1.9, 1.3.0.5, 1.4.0.10
IBM BladeCenter Advanced Management Module - update to 3.66u
FOS Firmware - update to 7.4.1c
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF037, 24.0.0-IF003
SnapDrive for Unix - update to 5.3.1
SnapDrive for Windows - update to 7.1.4
openssl - addressed in versions 0.9.8zh, 1.0.1q
openssl-solibs - addressed in versions 0.9.8zh, 1.0.1q
Integrated Management Module II (IMM2) - update to 1aoo72h-5.60
openssl101e - update to 1.0.1e-5.el5
openssl - addressed in versions 1.0.1k-13.fc22, 1.0.2e-1.fc23
FlashSystem 900 9840-AE2 and 9843-AE2 - addressed in versions 1.2.1.9, 1.3.0.5, 1.4.0.10
IBM BladeCenter Advanced Management Module - update to 3.66u
FOS Firmware - update to 7.4.1c
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF037, 24.0.0-IF003
External References
- https://git.openssl.org/?p=openssl.git;a=commit;h=d8541d7e9e63bf5f343af24644046c8d96498c17
- https://bugzilla.redhat.com/show_bug.cgi?id=1288320
- http://openssl.org/news/secadv/20151203.txt
- https://git.openssl.org/?p=openssl.git;a=commit;h=c394a488942387246653833359a5c94b5832674e
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA40100
- http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html
- http://marc.info/?l=bugtraq&m=145382583417444&w=2
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05157667
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05111017
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05131085
- http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html
- http://www.securityfocus.com/bid/91787
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05150888
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05158380
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04944173
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
- http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html
- http://www.securityfocus.com/bid/78623
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00053.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00009.html
- http://fortiguard.com/advisory/openssl-advisory-december-2015
- http://www.fortiguard.com/advisory/openssl-advisory-december-2015
- http://lists.opensuse.org/opensuse-updates/2015-12/msg00087.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-December/173801.html
- http://www.debian.org/security/2015/dsa-3413
- http://lists.opensuse.org/opensuse-updates/2015-12/msg00071.html
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151204-openssl
- http://rhn.redhat.com/errata/RHSA-2015-2617.html
- http://www.ubuntu.com/usn/USN-2830-1
- http://www.slackware.com/security/viewer.php?l=slackware-security&y=2015&m=slackware-security.754583
- http://lists.opensuse.org/opensuse-updates/2015-12/msg00070.html
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10759
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05398322
- http://www.securitytracker.com/id/1034294
- http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
- http://rhn.redhat.com/errata/RHSA-2016-2957.html
- https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdf
Related Security Bulletins
- Multiple vulnerabilities in N series Products
- Multiple vulnerabilities in IBM b-type SAN switches and directors
- NULL pointer dereference in IBM FlashSystem models 840 and 900
- Multiple vulnerabilities in IBM BladeCenter Advanced Management Module (AMM)
- Multiple vulnerabilities in IBM Integrated Management Module II (IMM2) for System x, Flex and BladeCenter systems
- Slackware Linux update for openssl
- Fedora 23 update for openssl
- Fedora 22 update for openssl
- Fedora EPEL 5 update for openssl101e
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation