CVE-2015-0209 is a use-after-free vulnerability in the d2i_ECPrivateKey function of OpenSSL versions before 0.9.8zf, 1.0.0r, 1.0.1m, and 1.0.2a. This flaw allows remote attackers to trigger a denial of service through memory corruption and application crashes, and potentially other unspecified impacts, by providing a malformed Elliptic Curve private-key file during import. The vulnerability has a CVSS score of 6.8, indicating a medium attack complexity and potential for partial confidentiality, integrity, and availability impacts. There is no evidence of active exploitation, public exploit code, or significant media coverage, though it has received some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.9.8zeCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* | ||
1.0.0CPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.0:*:*:*:*:*:*:* | ||
1.0.0aCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.0a:*:*:*:*:*:*:* | ||
1.0.0bCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.0b:*:*:*:*:*:*:* | ||
1.0.0cCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.0c:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.