CVE-2015-3195

Description

The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1q, and 1.0.2 before 1.0.2e mishandles errors caused by malformed X509_ATTRIBUTE data, which allows remote attackers to obtain sensitive information from process memory by triggering a decoding failure in a PKCS#7 or CMS application.

Risk Information

Base Score
5.3
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
EPSS Score
Exploitation Probability
3.481

Associated Vulnerability

VulnerabilityOS Platform
Update VM VirtualBox 5.0.14 to latest versionWindows
Vulnerabilities CVE-2015-3195 are fixed in OpenSSL (x64) 0.9.8zhWindows
Vulnerabilities CVE-2015-3195,CVE-2015-3194 are fixed in OpenSSL (x64) 1.0.1qWindows
Vulnerabilities CVE-2015-3195,CVE-2015-3194,CVE-2015-3193,CVE-2015-1794 are fixed in OpenSSL (x64) 1.0.2eWindows
Vulnerabilities CVE-2015-3196,CVE-2015-3195 are fixed in OpenSSL (x64) 1.0.0tWindows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 5.2Windows
Multiple vulnerabilities are affected in Oracle HTTP Server 5.0Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 10.2.1Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 10.1Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 10.1.1Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 10.2Windows
Multiple vulnerabilities are fixed in OS X El Capitan 10.11.4 UpdateMac
Multiple vulnerabilities are fixed in OS X El Capitan 10.11.4 Combo UpdateMac
Vulnerabilities CVE-2015-3195 are affected in Box For MAC 4.3.36Mac
Vulnerabilities CVE-2015-3195 are affected in Box For MAC 5.0.14Mac
Vulnerabilities CVE-2015-3195 are affected in VirtualBox for MAC 4.3.36Mac
Vulnerabilities CVE-2015-3195 are affected in VirtualBox for MAC 5.0.14Mac
Secure Socket Layer (SSL) cryptographic library and tools (USN-2830-1) libssl1.0.0_1.0.2d-0ubuntu1_i386.debLinux
Secure Socket Layer (SSL) cryptographic library and tools (USN-2830-1) libssl1.0.0_1.0.2d-0ubuntu1_amd64.debLinux
SUSE-SU-2016:0678-1(SUSE Linux Enterprise Desktop 12-SP1 ) sled-admin_en-pdf-12.1-7.2.noarch.rpmLinux
SUSE-SU-2016:0678-1(SUSE Linux Enterprise Desktop 12-SP1 ) sled-deployment_en-pdf-12.1-7.2.noarch.rpmLinux
SUSE-SU-2016:0678-1(SUSE Linux Enterprise Desktop 12-SP1 ) sled-gnomeuser_en-pdf-12.1-7.2.noarch.rpmLinux
SUSE-SU-2016:0678-1(SUSE Linux Enterprise Desktop 12-SP1 ) sled-installquick_en-pdf-12.1-7.2.noarch.rpmLinux
SUSE-SU-2016:0678-1(SUSE Linux Enterprise Desktop 12-SP1 ) sled-manuals_en-12.1-7.2.noarch.rpmLinux
SUSE-SU-2016:0678-1(SUSE Linux Enterprise Desktop 12-SP1 ) sled-security_en-pdf-12.1-7.2.noarch.rpmLinux
SUSE-SU-2016:0678-1(SUSE Linux Enterprise Desktop 12-SP1 ) sled-tuning_en-pdf-12.1-7.2.noarch.rpmLinux
SUSE-SU-2015:2251-1(SUSE Linux Enterprise Desktop 11-SP3 ) compat-openssl097g-0.9.7g-146.22.36.1.x86_64.rpmLinux
SUSE-SU-2015:2251-1(SUSE Linux Enterprise Desktop 11-SP3 ) compat-openssl097g-32bit-0.9.7g-146.22.36.1.x86_64.rpmLinux
SUSE-SU-2015:2275-1(SUSE Linux Enterprise Desktop 11-SP3 ) libopenssl0_9_8-0.9.8j-0.80.1.x86_64.rpmLinux
SUSE-SU-2015:2275-1(SUSE Linux Enterprise Desktop 11-SP3 ) libopenssl0_9_8-32bit-0.9.8j-0.80.1.x86_64.rpmLinux
SUSE-SU-2015:2275-1(SUSE Linux Enterprise Server 11-SP3 ) libopenssl0_9_8-hmac-0.9.8j-0.80.1.x86_64.rpmLinux
SUSE-SU-2015:2275-1(SUSE Linux Enterprise Server 11-SP3 ) libopenssl0_9_8-hmac-32bit-0.9.8j-0.80.1.x86_64.rpmLinux
SUSE-SU-2015:2275-1(SUSE Linux Enterprise Desktop 11-SP3 ) openssl-0.9.8j-0.80.1.x86_64.rpmLinux
SUSE-SU-2015:2275-1(SUSE Linux Enterprise Server 11-SP3 ) openssl-doc-0.9.8j-0.80.1.x86_64.rpmLinux
Multiple Vulnerabilities in OpenSSL (December 2015) Affecting Cisco Products For Cisco IOS XE SoftwareNCM
Multiple Vulnerabilities in OpenSSL (December 2015) Affecting Cisco Products For Cisco NX-OS SoftwareNCM
Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-3195)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-342239Oracle VM VirtualBox (7.1.4)
PATCH-1706107Security Update for Cisco IOS XE Software 5.2(1)SV5(1.3a)
PATCH-1706149Security Update for Cisco NX-OS Software 4.1(3a)UCSM
PATCH-600753OS X El Capitan 10.11.6 Update
PATCH-600754OS X El Capitan 10.11.6 Combo Update
PATCH-612038VirtualBox for MAC (Apple Silicon) (7.2.2)
PATCH-612038VirtualBox for MAC (Apple Silicon) (7.2.2)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234