PT-2015-1683 · Openssl+1 · Openssl+3

Per Allansson

·

Published

2015-03-19

·

Updated

2022-12-13

·

CVE-2015-0207

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions OpenSSL versions 1.0.2 through 1.0.2a (excluding 1.0.2a)
Description The issue is related to the dtls1 listen function in OpenSSL, which does not properly isolate state information of independent data streams. This can be exploited by a remote attacker to cause a denial of service via crafted DTLS traffic. The attacker can generate DTLS traffic to cause the application to crash due to incorrect pointer dereferences.
Recommendations For OpenSSL versions 1.0.2 through 1.0.2a (excluding 1.0.2a), update to version 1.0.2a or later to resolve the issue. As a temporary workaround, consider restricting DTLS traffic to minimize the risk of exploitation.

Fix

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

BDU:2015-11029
CVE-2015-0207

Affected Products

Cisco Asa
Cisco Ios Xe
Cisco Nexus
Openssl