1
PublicDateAtUSN: 2015-06-11
2
Candidate: CVE-2015-1789
6
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1789
7
https://www.openssl.org/news/secadv_20150611.txt
8
https://usn.ubuntu.com/usn/usn-2639-1
10
The X509_cmp_time function in crypto/x509/x509_vfy.c in OpenSSL before
11
0.9.8zg, 1.0.0 before 1.0.0s, 1.0.1 before 1.0.1n, and 1.0.2 before 1.0.2b
12
allows remote attackers to cause a denial of service (out-of-bounds read
13
and application crash) via a crafted length field in ASN1_TIME data, as
14
demonstrated by an attack against a server that supports client
15
authentication with a custom verification callback.
20
Discovered-by: Robert Swiecki and Hanno Böck
24
upstream_openssl: needs-triage
25
precise_openssl: released (1.0.1-4ubuntu5.31)
26
precise/esm_openssl: released (1.0.1-4ubuntu5.31)
27
trusty_openssl: released (1.0.1f-1ubuntu2.15)
28
utopic_openssl: released (1.0.1f-1ubuntu9.8)
29
vivid_openssl: released (1.0.1f-1ubuntu11.4)
30
vivid/stable-phone-overlay_openssl: released (1.0.1f-1ubuntu11.4)
31
vivid/ubuntu-core_openssl: released (1.0.1f-1ubuntu11.4)
32
wily_openssl: released (1.0.2c-1ubuntu1)
33
xenial_openssl: released (1.0.2c-1ubuntu1)
34
yakkety_openssl: released (1.0.2c-1ubuntu1)
35
zesty_openssl: released (1.0.2c-1ubuntu1)
36
artful_openssl: released (1.0.2c-1ubuntu1)
37
bionic_openssl: released (1.0.2c-1ubuntu1)
38
devel_openssl: released (1.0.2c-1ubuntu1)
41
upstream_openssl098: needs-triage
42
precise_openssl098: ignored (reached end-of-life)
43
precise/esm_openssl098: DNE (precise was needed)
44
trusty_openssl098: needed
45
utopic_openssl098: ignored (reached end-of-life)
46
vivid_openssl098: ignored (reached end-of-life)
47
vivid/stable-phone-overlay_openssl098: DNE
48
vivid/ubuntu-core_openssl098: DNE
50
xenial_openssl098: DNE
51
yakkety_openssl098: DNE
53
artful_openssl098: DNE
54
bionic_openssl098: DNE