PT-2020-7861 · Openssl · Libressl

Pascal Cuoq

·

Published

2020-01-23

·

Updated

2024-06-15

·

CVE-2015-5334

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: LibreSSL versions prior to 2.3.1
Description: The issue is caused by an off-by-one error in the OBJ obj2txt function, which can be triggered by a crafted X.509 certificate. This can lead to a denial of service (program crash) or potentially allow the execution of arbitrary code via a stack-based buffer overflow.
Recommendations: For versions prior to 2.3.1, update to version 2.3.1 or later to resolve the issue. As a temporary workaround, consider restricting the processing of crafted X.509 certificates to minimize the risk of exploitation.

Exploit

Fix

DoS

RCE

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-5334
OPENSUSE-SU-2024:10309-1

Affected Products

Libressl