OpenSSL CVE-2015-0208 NULL Pointer Dereference Denial of Service Vulnerability
BID:73230
Info
OpenSSL CVE-2015-0208 NULL Pointer Dereference Denial of Service Vulnerability
| Bugtraq ID: | 73230 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2015-0208 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 19 2015 12:00AM |
| Updated: | Jul 06 2016 02:12PM |
| Credit: | Brian Carpenter |
| Vulnerable: |
Oracle Enterprise Manager Ops Center 11.1 OpenSSL Project OpenSSL 1.0.2 IBM Cognos TM1 9.5.2 HP Systems Insight Manager 7.0 HP System Management Homepage 7.0 Avaya Aura Session Manager 6.2 Avaya Aura Experience Portal 6.0 |
| Not Vulnerable: | |
Discussion
OpenSSL CVE-2015-0208 NULL Pointer Dereference Denial of Service Vulnerability
OpenSSL is prone to denial-of-service vulnerability due to a NULL pointer dereference condition.
An attacker may exploit this issue to crash the application, resulting in denial-of-service conditions.
OpenSSL is prone to denial-of-service vulnerability due to a NULL pointer dereference condition.
An attacker may exploit this issue to crash the application, resulting in denial-of-service conditions.
Exploit / POC
OpenSSL CVE-2015-0208 NULL Pointer Dereference Denial of Service Vulnerability
An attacker can use readily available tools to exploit this issue.
An attacker can use readily available tools to exploit this issue.
Solution / Fix
OpenSSL CVE-2015-0208 NULL Pointer Dereference Denial of Service Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
OpenSSL CVE-2015-0208 NULL Pointer Dereference Denial of Service Vulnerability
References:
References:
- OpenSSL Homepage (OpenSSL)
- Security Bulletin: Vulnerabilities in OpenSSL (Aspera)
- HP System Management Homepage (SMH) on Linux and Windows, Multiple Vulnerabiliti (HP)
- HPSBMU03397 rev.1 - HP Version Control Agent (VCA) on Windows and Linux, Multipl (HP)
- HPSBMU03409 rev.1 - HP Matrix Operating Environment, Multiple Vulnerabilities (hp)
- IBM Advisory swg21966177 (IBM)
- IBM i is affected by several OpenSSL vulnerabilities. (IBM)
- OpenSSL Security Advisory [19 Mar 2015] (OpenSSL )
- OpenSSL vulnerabilities (OpenSSL)
- Oracle Critical Patch Update Advisory - January 2016 (Oracle)
- Security Bulletin: Multiple Security Issues in IBM Media Server Due to OpenSSL I (IBM)
- Security Bulletin: Multiple vulnerabilities impact DS8000 HMC (IBM)
- Security Bulletin: Vulnerabilities in OpenSSL affect IBM Flex System FC5022 16Gb (IBM)
- Security Bulletin: Vulnerabilities in OpenSSL affect QLogic 8Gb Intelligent Pass (IBM)
- Security Bulletin: Vulnerabilities in OpenSSL affect the Cordova platform packag (IBM)
- Security Bulletin: Vulnerabilities in OpenSSL including ClientHello DoS affect I (IBM)
- swg21964686 - Security Bulletin: Vulnerabilities in OpenSSL affecting Sametime U (IBM)
- Vulnerabilities in OpenSSL affect Rational Tau (CVE-2015-0208, CVE-2015-0286, CV (ibm)
- Vulnerabilities in OpenSSL affects Rational Application Developer for WebSphere (IBM)
- Vulnerabilities in OpenSSL affects Rational Software Architect for Websphere Sof (IBM)