PT-2013-1154 · Openssl+7 · Openssl+10

Chris Mueller

·

Publicado

2013-12-01

·

Atualizado

2024-06-15

·

CVE-2015-0206

CVSS v2.0

7.1

Alta

VetorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions OpenSSL versions 1.0.0 through 1.0.0p OpenSSL versions 1.0.1 through 1.0.1k openssl-1.0.1e openssl-devel-1.0.1e openssl-static-1.0.1e openssl-libs-1.0.1e openssl-debuginfo-1.0.1e
Description The issue is related to multiple vulnerabilities in the OpenSSL package, which can be exploited remotely to cause a denial of service or gain access to encrypted data without knowing the encryption key. The vulnerabilities can lead to a memory leak, allowing attackers to consume memory and cause a failure in replay detection. The estimated number of potentially affected devices worldwide is not specified. There is no information about real-world incidents where this issue was exploited.
Recommendations For OpenSSL versions 1.0.0 through 1.0.0p, update to version 1.0.0p or later. For OpenSSL versions 1.0.1 through 1.0.1k, update to version 1.0.1k or later. For openssl-1.0.1e, openssl-devel-1.0.1e, openssl-static-1.0.1e, openssl-libs-1.0.1e, and openssl-debuginfo-1.0.1e, update to a version that is not affected by the vulnerabilities. As a temporary workaround, consider restricting access to the vulnerable OpenSSL package until a patch is available.

Exploit

Correção

DoS

Buffer Overflow

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2015-1023
BDU:2015-06127
BDU:2015-06128
BDU:2015-06129
BDU:2015-06130
BDU:2015-06131
BDU:2015-09142
BDU:2015-09143
BDU:2015-09144
BDU:2015-09145
BDU:2015-09146
BDU:2015-09819
BDU:2015-09905
CESA-2015_0066
CVE-2015-0206
DSA-3125-1
MGASA-2015-0022
OPENSUSE-SU-2015_0130-1
OPENSUSE-SU-2015_1277-1
OPENSUSE-SU-2024:10271-1
OPENSUSE-SU-2024:10309-1
OPENSUSE-SU-2024:10529-1
OPENSUSE-SU-2024:11127-1
RHSA-2015:0066
RHSA-2015_0066
SUSE-FU-2022:0445-1
SUSE-RU-2015:0769-1
SUSE-SU-2015:0546-1
SUSE-SU-2015:0620-1
SUSE-SU-2015:0946-1
SUSE-SU-2015:1177-1
SUSE-SU-2015:1185-1
USN-2459-1

Produtos afetados

Alt Linux
Centos
Cisco Asa
Cisco Ios
Cisco Ios Xe
Cisco Nexus
Ibm Aix
Openssl
Red Hat
Suse
Ubuntu