Errata ID | 142 |
---|---|
Date | 2015-03-25 |
Source package | openssl |
Fixed in version | 1.0.1e-2.99.201503250939 |
Description | Multiple vulnerabilities have been found in OpenSSL: * NULL pointer dereference in elliptic curves (CVE-2015-0209) * Denial of service during certificate signature algorithm verification in ASN1_TYPE_cmp function (CVE-2015-0286) * Memory corruption in ASN.1 parsing (CVE-2015-0287) * NULL pointer dereference in X509 parsing (CVE-2015-0288) * Denial of service due to NULL pointer dereference in PKCS#7 parsing code (CVE-2015-0289) * Memory corruption due to missing input sanitising in base64 decoding (CVE-2015-0292) |
Additional notes | |
CVE ID | CVE-2015-0209 CVE-2015-0286 CVE-2015-0287 CVE-2015-0288 CVE-2015-0289 CVE-2015-0292 |
UCS Bug number | #37960 |