Lucene search

K
kasperskyKaspersky LabKLA10479
HistoryMar 19, 2015 - 12:00 a.m.

KLA10479 Multiple vulnerabilities in OpenSSL

2015-03-1900:00:00
Kaspersky Lab
threats.kaspersky.com
103

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.7 High

AI Score

Confidence

High

0.944 High

EPSS

Percentile

99.2%

Multiple serious vulnerabilities have been found in OpenSSL. Malicious users can exploit these vulnerabilities to caused denial of service or bypass security restrictions.

Below is a complete list of vulnerabilities

  1. An unknown vulnerability can be exploited remotely via a specially designed message, certificate key or RSA PSS parameters;
  2. Integer underflow can be exploited remotely via a specially designed base64 data;
  3. Improper handling IO cases can be exploited remotely via an unknown vectors;
  4. Improper handling of ContentInfo can be exploited remotely via a specailly designed data;
  5. Improper handling of data structures and boolean-type comparisons can be exploited via an unknown vectors related to ASN.1 structure;
  6. Lack of PRNG restrictions can be exploited remotely via a specially designed private-key;
  7. Improper isolation of state information can be exploited remotely via a specially designed DTLS traffic.

Original advisories

OpenSSL bulletin

Exploitation

Malware exists for this vulnerability. Usually such malware is classified as Exploit. More details.

Related products

OpenSSl

CVE list

CVE-2015-0207 warning

CVE-2015-0208 warning

CVE-2015-0209 high

CVE-2015-0288 warning

CVE-2015-0287 warning

CVE-2015-0290 warning

CVE-2015-0289 warning

CVE-2015-0292 high

CVE-2015-0291 warning

CVE-2015-0293 warning

CVE-2015-1787 warning

CVE-2015-0286 warning

CVE-2015-0285 warning

Solution

Update to latest version!

Get OpenSSL

Impacts

  • OSI

Obtain sensitive information. Exploitation of vulnerabilities with this impact can lead to capturing by abuser information, critical for user or system.

  • DoS

Denial of service. Exploitation of vulnerabilities with this impact can lead to loss of system availability or critical functional fault.

  • SB

Security bypass. Exploitation of vulnerabilities with this impact can lead to performing actions restricted by current security settings.

  • LoI

Loss of integrity. Exploitation of vulnerabilities with this impact can lead to partial system fault or system components connection disruption.

Affected Products

  • OpenSSL 1.0.2 versions earlier than 1.0.2aOpenSSL 1.0.1 versions earlier than 1.0.1mOpenSSL 1.0.0 versions earlier than 1.0.0rOpenSSL versions earlier than 0.9.8zf

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.7 High

AI Score

Confidence

High

0.944 High

EPSS

Percentile

99.2%