Information disclosure in OpenSSL - CVE-2015-3195

 

Information disclosure in OpenSSL - CVE-2015-3195

Published: June 20, 2023


Vulnerability identifier: #VU77552
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-3195
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists in the ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL. A remote attacker can gain unauthorized access to sensitive information from process memory by triggering a decoding failure in a PKCS#7 or CMS application.


Affected software

OpenSSL
Fedora
Slackware Linux
SnapDrive for Unix
SnapDrive for Windows
Integrated Management Module II (IMM2)
Oracle HTTP Server
IBM BladeCenter Advanced Management Module
IBM Cloud Pak for Business Automation
openssl
openssl-solibs
openssl101e
FOS Firmware

How to mitigate CVE-2015-3195

Install updates from vendor's website.

OpenSSL - addressed in versions 0.9.8zh, 1.0.0t, 1.0.1q, 1.0.2e
SnapDrive for Unix - update to 5.3.1
SnapDrive for Windows - update to 7.1.4
openssl - addressed in versions 0.9.8zh, 1.0.1q
openssl-solibs - addressed in versions 0.9.8zh, 1.0.1q
Integrated Management Module II (IMM2) - update to 1aoo72h-5.60
openssl101e - update to 1.0.1e-5.el5
openssl - addressed in versions 1.0.1k-13.fc22, 1.0.2e-1.fc23
IBM BladeCenter Advanced Management Module - update to 3.66u
FOS Firmware - update to 7.4.1c
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF037, 24.0.0-IF003

External References

Related Security Bulletins