CVE-2015-1789 is a denial-of-service vulnerability in the X509_cmp_time function of OpenSSL versions prior to 0.9.8zg, 1.0.0s, 1.0.1n, and 1.0.2b, affecting various OpenSSL and Oracle products. A remote attacker can trigger an out-of-bounds read and application crash by sending crafted ASN1_TIME data, particularly against servers using custom client authentication callbacks. This vulnerability has a CVSS score of 7.5 (High), indicating a network-based attack with low complexity and high impact on availability. While there is no evidence of active exploitation, public exploit code, or Metasploit/Nuclei modules, the vulnerability has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.9.8zfCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* | ||
1.0.0CPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.0:*:*:*:*:*:*:* | ||
1.0.0CPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.0:beta1:*:*:*:*:*:* | ||
1.0.0CPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.0:beta2:*:*:*:*:*:* | ||
1.0.0CPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.0:beta3:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.