CVE-2015-0292

OpenSSL < 0.9.8za, 1.0.0 < 1.0.0m, 1.0.1 < 1.0.1h - Memory Corruption via Base64 Decoding

Title source: llm
STIX 2.1

Description

Integer underflow in the EVP_DecodeUpdate function in crypto/evp/encode.c in the base64-decoding implementation in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via crafted base64 data that triggers a buffer overflow.

References (34)

Core 34
Core References
Third Party Advisory vendor-advisory
https://security.gentoo.org/glsa/201503-11
Vendor Advisory vendor-advisory
http://rhn.redhat.com/errata/RHSA-2015-0715.html
Vendor Advisory vendor-advisory
http://rhn.redhat.com/errata/RHSA-2015-0716.html
Vendor Advisory vendor-advisory
http://rhn.redhat.com/errata/RHSA-2015-0752.html
Vendor Advisory vendor-advisory
http://rhn.redhat.com/errata/RHSA-2015-0800.html
Third Party Advisory vendor-advisory
http://www.debian.org/security/2015/dsa-3197
Vendor Advisory vendor-advisory
http://www.ubuntu.com/usn/USN-2537-1
Third Party Advisory, VDB Entry vdb-entry
http://www.securityfocus.com/bid/73228
Third Party Advisory, VDB Entry vdb-entry
http://www.securitytracker.com/id/1031929

Scores

EPSS 0.0654
EPSS Percentile 91.2%

Details

CWE
CWE-119
Status published
Products (22)
openssl/openssl 1.0.0
openssl/openssl 1.0.0a
openssl/openssl 1.0.0b
openssl/openssl 1.0.0c
openssl/openssl 1.0.0d
openssl/openssl 1.0.0e
openssl/openssl 1.0.0f
openssl/openssl 1.0.0g
openssl/openssl 1.0.0h
openssl/openssl 1.0.0i
... and 12 more
Published Mar 19, 2015
Tracked Since Feb 18, 2026