OpenSSL CVE-2015-0291 Denial of Service Vulnerability

BID:73235

Info

OpenSSL CVE-2015-0291 Denial of Service Vulnerability

Bugtraq ID: 73235
Class: Design Error
CVE: CVE-2015-0291
Remote: Yes
Local: No
Published: Mar 19 2015 12:00AM
Updated: May 23 2017 04:24PM
Credit: David Ramos of Stanford University
Vulnerable: Rockwell Automation Stratix 5900 0
Oracle Enterprise Manager Ops Center 12.1.0.1
Oracle Enterprise Manager Ops Center 12.1
Oracle Enterprise Manager Ops Center 11.1.3
Oracle Enterprise Manager Ops Center 11.1
Oracle Endeca Server 7.4
Oracle Endeca Server 7.6.1.0.0
Oracle Endeca Server 7.5.1.1
Oracle Endeca Server 7.3.0
Oracle Business Intelligence Enterprise Edition 11.1.1.9
Oracle Business Intelligence Enterprise Edition 11.1.1.7
OpenSSL Project OpenSSL 1.0.2
IBM TotalStorage SAN256B Director Model M48 0
IBM Tivoli Workload Scheduler Distributed 9.2
IBM Tivoli Workload Scheduler Distributed 8.6
IBM Tivoli Workload Scheduler Distributed 8.5.1 FP04
IBM Tivoli Workload Scheduler Distributed 8.5.1
IBM Tivoli Workload Scheduler Distributed 8.5 FP05
IBM Tivoli Workload Scheduler Distributed 8.5
IBM Tivoli Workload Scheduler Distributed 9.2.0 FP01
IBM Tivoli Workload Scheduler Distributed 9.1.0 FP01
IBM Tivoli Workload Scheduler Distributed 9.1
IBM Tivoli Workload Scheduler Distributed 8.6.0 FP03
IBM Tivoli Workload Scheduler Distributed 8.6 FP02
IBM Tivoli Workload Scheduler Distributed 8.6
IBM Tivoli Workload Scheduler Distributed 8.5.1 FP05
IBM Tivoli Workload Scheduler Distributed 8.5 FP04
IBM Tivoli Workload Scheduler Distributed 8.5 FP03
IBM Tivoli Workload Scheduler Distributed 8.5
IBM System Storage SAN80B-4 0
IBM System Storage SAN768B-2 0
IBM System Storage SAN768B 0
IBM System Storage SAN48B-5 0
IBM System Storage SAN42B-R 0
IBM System Storage SAN40B-4 0
IBM System Storage SAN384B-2 0
IBM System Storage SAN384B 0
IBM System Storage SAN24B-4 0
IBM System Storage SAN06B-R 0
IBM System Storage SAN04B-R 0
IBM System Networking SAN96B-5 0
IBM System Networking SAN24B-5 0
IBM Sterling Integrator 5.1
IBM Sterling B2B Integrator 5.2
IBM Encryption Switch 0
HP Virtual Connect Enterprise Manager SDK 7.4.1
HP Virtual Connect Enterprise Manager SDK 7.4
HP Version Control Repository Manager 7.4.1
HP Version Control Repository Manager 7.4
HP Version Control Repository Manager 7.3.4
HP Version Control Repository Manager 7.3.1
HP Version Control Repository Manager 7.3
HP Version Control Repository Manager 7.2.2
HP Version Control Repository Manager 7.2.1
HP Version Control Repository Manager 7.2
HP Version Control Repository Manager 7.4.0a
HP Version Control Repository Manager 7.3.3
HP Version Control Repository Manager 7.3.2
HP Version Control Agent 7.3.4
HP Version Control Agent 7.3.3
HP Version Control Agent 7.3.1
HP Version Control Agent 7.3
HP Version Control Agent 7.2.2
HP Version Control Agent 7.2.1
HP Version Control Agent 7.2
HP Version Control Agent 7.3.2
HP Systems Insight Manager 7.1.1
HP Systems Insight Manager 7.4.0a
HP Systems Insight Manager 7.4
HP Systems Insight Manager 7.3.2
HP Systems Insight Manager 7.3.1
HP Systems Insight Manager 7.3.0a
HP Systems Insight Manager 7.3
HP Systems Insight Manager 7.2.2
HP Systems Insight Manager 7.2.1
HP Systems Insight Manager 7.2
HP Systems Insight Manager 7.0
HP System Management Homepage (SMH) 7.4
HP System Management Homepage 7.4.1
HP System Management Homepage 7.3.2
HP System Management Homepage 7.2.3
HP System Management Homepage 7.2.2
HP System Management Homepage 7.2.1
HP System Management Homepage 7.2
HP System Management Homepage 7.1.2
HP System Management Homepage 7.1.1
HP System Management Homepage 7.4.0a
HP System Management Homepage 7.4
HP System Management Homepage 7.3.3.1
HP System Management Homepage 7.3.1
HP System Management Homepage 7.3
HP System Management Homepage 7.2.4.1
HP System Management Homepage 7.2
HP System Management Homepage 7.1
HP System Management Homepage 7.0
HP Insight Orchestration 0
Avaya Session Border Controller for Enterprise 6.3.0
Avaya one-X Client Enablement Services 6.2
Avaya IP Office Server Edition 9.0
Avaya IP Office Server Edition 8.1
Avaya IP Office Application Server 9.0
Avaya CMS 17.0
Avaya Aura Session Manager 6.2
Avaya Aura Experience Portal 7.0
Avaya Aura Experience Portal 6.0
Avaya Aura Conferencing 8.0
Avaya Aura Collaboration Environment 3.0
Avaya Aura Collaboration Environment 2.0
Not Vulnerable: Rockwell Automation Stratix 5900 15.6.3
Oracle Enterprise Manager Ops Center 12.3
Oracle Enterprise Manager Ops Center 12.2.1
Oracle Enterprise Manager Ops Center 12.2
Oracle Enterprise Manager Ops Center 12.1.4
OpenSSL Project OpenSSL 1.0.2a
HP Virtual Connect Enterprise Manager SDK 7.5.0
HP Version Control Repository Manager 7.5.0
HP Version Control Agent 7.3.5
HP Version Control Agent 7.5.0
HP Systems Insight Manager 7.5.0
HP System Management Homepage (SMH) 7.5
HP System Management Homepage 7.5
HP Insight Orchestration 7.5.0

Discussion

OpenSSL CVE-2015-0291 Denial of Service Vulnerability

OpenSSL is prone to denial-of-service vulnerability.

Note: This issue was previously discussed in BID 73196 (OpenSSL Multiple Unspecified Security Vulnerabilities) but has been given its own record to better document it.

An attacker may exploit this issue to cause a denial-of-service condition.

Exploit / POC

OpenSSL CVE-2015-0291 Denial of Service Vulnerability

An attacker can use readily available tools to exploit this issue.

Solution / Fix

OpenSSL CVE-2015-0291 Denial of Service Vulnerability

Solution:
Updates are available. Please see the references or vendor advisory for more information.

References

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report