Beschreibung
Multiple serious vulnerabilities have been found in OpenSSL. Malicious users can exploit these vulnerabilities to caused denial of service or bypass security restrictions.
Below is a complete list of vulnerabilities
- An unknown vulnerability can be exploited remotely via a specially designed message, certificate key or RSA PSS parameters;
- Integer underflow can be exploited remotely via a specially designed base64 data;
- Improper handling IO cases can be exploited remotely via an unknown vectors;
- Improper handling of ContentInfo can be exploited remotely via a specailly designed data;
- Improper handling of data structures and boolean-type comparisons can be exploited via an unknown vectors related to ASN.1 structure;
- Lack of PRNG restrictions can be exploited remotely via a specially designed private-key;
- Improper isolation of state information can be exploited remotely via a specially designed DTLS traffic.
Ursprüngliche Informationshinweise
CVE Liste
- CVE-2015-0207 critical
- CVE-2015-0208 critical
- CVE-2015-0209 critical
- CVE-2015-0288 critical
- CVE-2015-0287 critical
- CVE-2015-0290 critical
- CVE-2015-0289 critical
- CVE-2015-0292 critical
- CVE-2015-0291 critical
- CVE-2015-0293 critical
- CVE-2015-1787 critical
- CVE-2015-0286 critical
- CVE-2015-0285 critical
Mehr erfahren
Informieren Sie sich über die Statistiken der in Ihrer Region verbreiteten Sicherheitslücken statistics.securelist.com
Sie haben einen Fehler in der Beschreibung der Schwachstelle gefunden? Mitteilen!