CVE-2015-0206 is a memory leak vulnerability in the dtls1_buffer_record function of OpenSSL versions 1.0.0 before 1.0.0p and 1.0.1 before 1.0.1k. This flaw allows remote attackers to cause a denial of service by sending numerous duplicate records, leading to excessive memory consumption. With a CVSS score of 5.0, it is a low-severity vulnerability that requires no authentication and has a low attack complexity, primarily impacting availability. There is no evidence of active exploitation, public exploit code, or inclusion in the KEV catalog, though it garnered some community discussion and media coverage at the time of disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.0aCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.0a:*:*:*:*:*:*:* | ||
1.0.0bCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.0b:*:*:*:*:*:*:* | ||
1.0.0cCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.0c:*:*:*:*:*:*:* | ||
1.0.0dCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.0d:*:*:*:*:*:*:* | ||
1.0.0eCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.0e:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.