CVE-2015-1788

Description

The BN_GF2m_mod_inv function in crypto/bn/bn_gf2m.c in OpenSSL before 0.9.8s, 1.0.0 before 1.0.0e, 1.0.1 before 1.0.1n, and 1.0.2 before 1.0.2b does not properly handle ECParameters structures in which the curve is over a malformed binary polynomial field, which allows remote attackers to cause a denial of service (infinite loop) via a session that uses an Elliptic Curve algorithm, as demonstrated by an attack against a server that supports client authentication.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
16.102

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities fixed in OpenSSL (x64) 0.9.8sWindows
Vulnerabilities CVE-2015-1788,CVE-2011-3210,CVE-2011-3207 are fixed in OpenSSL (x64) 1.0.0eWindows
Vulnerabilities CVE-2015-1792,CVE-2015-1790,CVE-2015-1789,CVE-2015-1788,CVE-2015-1791 are fixed in OpenSSL (x64) 1.0.1nWindows
Vulnerabilities CVE-2015-1792,CVE-2015-1790,CVE-2015-1789,CVE-2015-1788,CVE-2015-1791 are fixed in OpenSSL (x64) 1.0.2bWindows
Multiple vulnerabilities are fixed in IBM HTTP 8.5.5.7Windows
Multiple vulnerabilities are fixed in IBM HTTP 8.0.0.12Windows
Multiple Vulnerabilities are affected in IBM Tivoli Monitoring 6.30Windows
Multiple Vulnerabilities are affected in IBM TXSeries for Multiplatforms 7.1Windows
Multiple vulnerabilities are fixed in OS X Yosemite 10.10.5 UpdateMac
Multiple vulnerabilities are fixed in OS X Yosemite 10.10.5 Combo UpdateMac
Multiple Vulnerabilities in OpenSSL (June 2015) Affecting Cisco Products For Cisco IOS XE SoftwareNCM
Multiple Vulnerabilities in OpenSSL (June 2015) Affecting Cisco Products For Cisco NX-OS SoftwareNCM
CVE-2015-1788NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-1706107Security Update for Cisco IOS XE Software 5.2(1)SV5(1.3a)
PATCH-1706149Security Update for Cisco NX-OS Software 4.1(3a)UCSM
PATCH-600354OS X Yosemite 10.10.5 Update
PATCH-600458OS X Yosemite 10.10.5 Combo Update

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234