CVE-2015-5334 is an off-by-one error in the OBJ_obj2txt function of LibreSSL versions prior to 2.3.1, affecting OpenBSD and openSUSE distributions. This vulnerability, stemming from an incorrect fix for CVE-2014-3508, allows remote attackers to trigger a stack-based buffer overflow via a crafted X.509 certificate. With a CVSS score of 9.8 (Critical), it poses a significant risk of denial of service or potential arbitrary code execution, requiring no user interaction or authentication. While no public exploit code or active exploitation has been identified, the vulnerability has garnered some community discussion, indicating awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.3.1CPE matchmatch criteria | cpe:2.3:a:openbsd:libressl:*:*:*:*:*:*:*:* | ||
13.2CPE matchmatch criteria | cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.