Lucene search

K
opensslOpenSSLOPENSSL:CVE-2015-1790
HistoryJun 11, 2015 - 12:00 a.m.

Vulnerability in OpenSSL - PKCS7 crash with missing EnvelopedContent

2015-06-1100:00:00
www.openssl-library.org
37

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

AI Score

6.7

Confidence

High

EPSS

0.433

Percentile

97.4%

The PKCS#7 parsing code does not handle missing inner EncryptedContent correctly. An attacker can craft malformed ASN.1-encoded PKCS#7 blobs with missing content and trigger a NULL pointer dereference on parsing. Applications that decrypt PKCS#7 data or otherwise parse PKCS#7 structures from untrusted sources are affected. OpenSSL clients and servers are not affected.

Found by Michal Zalewski (Google).

Affected configurations

Vulners
Node
opensslopensslRange1.0.21.0.2b
OR
opensslopensslRange1.0.11.0.1n
OR
opensslopensslRange1.0.01.0.0s
OR
opensslopensslRange0.9.80.9.8zg
VendorProductVersionCPE
opensslopenssl*cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

AI Score

6.7

Confidence

High

EPSS

0.433

Percentile

97.4%