Information Exposure Affecting openssl package, versions >=1.0.200, <1.0.205
Snyk CVSS
Attack Complexity
Low
Threat Intelligence
EPSS
0.45% (73rd
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-COCOAPODS-OPENSSL-471033
- published 2 Oct 2019
- disclosed 3 Dec 2015
- credit Unknown
Introduced: 3 Dec 2015
CVE-2015-3193 Open this link in a new tabHow to fix?
Upgrade OpenSSL
to version 1.0.205 or higher.
Overview
OpenSSL is a SSL/TLS and Crypto toolkit. Deprecated in Mac OS and gone in iOS, this spec gives your project non-deprecated OpenSSL support.
Affected versions of this package are vulnerable to Information Exposure. OpenSSL is vulnerable to information disclosure. The library contains a carry propagation bug during the montgomery squaring procedure. This makes it easier for a malicious user to obtain sensitive private key information from the Diffie-Hellman and Diffie-Hellman Ephemereal Ciphersuites.
References
- HPE Support Center Security Bulletin
- http://fortiguard.com/advisory/openssl-advisory-december-2015
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10759
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761
- https://blog.fuzzing-project.org/31-Fuzzing-Math-miscalculations-in-OpenSSLs-BN_mod_exp-CVE-2015-3193.html
- https://git.openssl.org/?p=openssl.git;a=commit;h=d73cc256c8e256c32ed959456101b73ba9842f72
- https://kb.isc.org/article/AA-01438
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA40100
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151204-openssl
- http://www.fortiguard.com/advisory/openssl-advisory-december-2015
- http://www.slackware.com/security/viewer.php?l=slackware-security&y=2015&m=slackware-security.539966
- http://www.slackware.com/security/viewer.php?l=slackware-security&y=2015&m=slackware-security.754583
- OpenSSL Security Advisory
- Oracle Security Advisory
- Oracle Security Advisory
- Oracle Security Advisory
- RedHat Bugzilla Bug
- Security Focus
- Security Focus
- Security Tracker
- Ubuntu Security Advisory