CVE-2015-1789: Buffer Overflow
Last updated 24 July 2024
Other sources
The X509cmptime function in crypto/x509/x509vfy.c in OpenSSL before 0.9.8zg, 1.0.0 before 1.0.0s, 1.0.1 before 1.0.1n, and 1.0.2 before 1.0.2b allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted length field in ASN1TIME data, as demonstrated by an attack against a server that supports client authentication with a custom verification callback.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1789?
CVE-2015-1789 has a severity rating that indicates a denial of service risk due to an out-of-bounds read affecting certain versions of OpenSSL.
How do I fix CVE-2015-1789?
To fix CVE-2015-1789, update OpenSSL to version 0.9.8zg or newer, or to version 1.0.0s, 1.0.1n, or 1.0.2b and above.
What systems are affected by CVE-2015-1789?
CVE-2015-1789 affects various versions of OpenSSL including those prior to 0.9.8zg and specific 1.0.0, 1.0.1, and 1.0.2 versions.
What kind of attacks can exploit CVE-2015-1789?
CVE-2015-1789 can be exploited by remote attackers to cause a denial of service via a specially crafted length field.
Is CVE-2015-1789 still a concern on updated systems?
No, CVE-2015-1789 is no longer a concern if systems are updated to the recommended versions of OpenSSL.