CVE-2015-0292

Description

Integer underflow in the EVP_DecodeUpdate function in crypto/evp/encode.c in the base64-decoding implementation in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via crafted base64 data that triggers a buffer overflow.

Risk Information

Base Score
8.2
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
EPSS Score
Exploitation Probability
6.629

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities fixed in OpenSSL (x64) 0.9.8zaWindows
Multiple vulnerabilities fixed in OpenSSL (x64) 1.0.0mWindows
Multiple vulnerabilities fixed in OpenSSL (x64) 1.0.1hWindows
Multiple Vulnerabilities in OpenSSL (March 2015) Affecting Cisco Products For Cisco IOSNCM
Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2015-0292)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-1706090Security Update for Cisco IOS Amsterdam-17.2.1r

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234