CVE-2015-0291

OpenSSL 1.0.2 - Denial of Service via Invalid signature_algorithms Extension

Title source: llm
STIX 2.1

Description

The sigalgs implementation in t1_lib.c in OpenSSL 1.0.2 before 1.0.2a allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) by using an invalid signature_algorithms extension in the ClientHello message during a renegotiation.

References (18)

Core 18
Core References
Third Party Advisory, VDB Entry vdb-entry
http://www.securityfocus.com/bid/73235
Mailing List, Third Party Advisory vendor-advisory
http://marc.info/?l=bugtraq&m=144050155601375&w=2
Mailing List, Third Party Advisory vendor-advisory
http://marc.info/?l=bugtraq&m=143748090628601&w=2
Mailing List, Third Party Advisory vendor-advisory
http://marc.info/?l=bugtraq&m=144050297101809&w=2
Third Party Advisory, VDB Entry vdb-entry
http://www.securitytracker.com/id/1031929
Third Party Advisory vendor-advisory
https://security.gentoo.org/glsa/201503-11

Scores

EPSS 0.2803
EPSS Percentile 96.5%

Details

Status published
Products (1)
openssl/openssl 1.0.2 (4 CPE variants)
Published Mar 19, 2015
Tracked Since Feb 18, 2026