CVE-2015-1794: Medium severity OpenSSL OpenSSL vulnerability
Published Dec 6, 2015
·Updated
The ssl3getkeyexchange function in ssl/s3clnt.c in OpenSSL 1.0.2 before 1.0.2e allows remote servers to cause a denial of service (segmentation fault) via a zero p value in an anonymous Diffie-Hellman (DH) ServerKeyExchange message.
Affected Software
5 affected components
OpenSSL OpenSSL=1.0.2
OpenSSL OpenSSL=1.0.2a
OpenSSL OpenSSL=1.0.2b
OpenSSL OpenSSL=1.0.2c
OpenSSL OpenSSL=1.0.2d
Event History
Dec 6, 2015
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-1794?
CVE-2015-1794 is classified as a medium severity vulnerability due to its potential to cause denial of service.
2
How do I fix CVE-2015-1794?
To fix CVE-2015-1794, upgrade OpenSSL to version 1.0.2e or later.
3
Which versions of OpenSSL are affected by CVE-2015-1794?
OpenSSL versions 1.0.2, 1.0.2a, 1.0.2b, 1.0.2c, and 1.0.2d are affected by CVE-2015-1794.
4
What type of attack does CVE-2015-1794 enable?
CVE-2015-1794 enables a remote denial of service attack via a segmentation fault.
5
Is CVE-2015-1794 a local or remote vulnerability?
CVE-2015-1794 is a remote vulnerability, allowing attackers to exploit it over the network.