CVE-2015-1788: Medium severity OpenSSL OpenSSL vulnerability
The BNGF2mmodinv function in crypto/bn/bngf2m.c in OpenSSL before 0.9.8s, 1.0.0 before 1.0.0e, 1.0.1 before 1.0.1n, and 1.0.2 before 1.0.2b does not properly handle ECParameters structures in which the curve is over a malformed binary polynomial field, which allows remote attackers to cause a denial of service (infinite loop) via a session that uses an Elliptic Curve algorithm, as demonstrated by an attack against a server that supports client authentication.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1788?
CVE-2015-1788 is rated as medium severity due to its potential ability to cause denial of service.
How do I fix CVE-2015-1788?
To fix CVE-2015-1788, upgrade OpenSSL to version 1.0.2 or later.
Which OpenSSL versions are affected by CVE-2015-1788?
OpenSSL versions prior to 0.9.8s, 1.0.0e, 1.0.1n, and 1.0.2b are affected by CVE-2015-1788.
Can CVE-2015-1788 be exploited remotely?
Yes, CVE-2015-1788 can be exploited remotely, allowing attackers to potentially cause a denial of service.
What systems are vulnerable to CVE-2015-1788?
Various systems using vulnerable versions of OpenSSL, particularly older Ubuntu and Debian distributions, are at risk from CVE-2015-1788.