CVE-2015-1790: Null Pointer Dereference
The PKCS7dataDecodefunction in crypto/pkcs7/pk7doit.c in OpenSSL before 0.9.8zg, 1.0.0 before 1.0.0s, 1.0.1 before 1.0.1n, and 1.0.2 before 1.0.2b allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a PKCS#7 blob that uses ASN.1 encoding and lacks inner EncryptedContent data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1790?
CVE-2015-1790 is classified as a severity level that allows remote attackers to cause denial of service through a NULL pointer dereference.
How do I fix CVE-2015-1790?
To fix CVE-2015-1790, upgrade OpenSSL to version 1.0.2 or later.
Which versions of OpenSSL are affected by CVE-2015-1790?
OpenSSL versions prior to 0.9.8zg, 1.0.0 before 1.0.0s, 1.0.1 before 1.0.1n, and 1.0.2 before 1.0.2b are affected by CVE-2015-1790.
What type of attack does CVE-2015-1790 enable?
CVE-2015-1790 enables a denial of service attack due to an application crash caused by a malformed PKCS#7 blob.
Is CVE-2015-1790 specific to any operating system?
CVE-2015-1790 affects multiple operating systems that utilize vulnerable versions of OpenSSL.