CVE-2015-0287 is a denial-of-service vulnerability affecting OpenSSL versions prior to 0.9.8zf, 1.0.0r, 1.0.1m, and 1.0.2a. The flaw in the ASN1_item_ex_d2i function, specifically its failure to reinitialize CHOICE and ADB data structures, could lead to memory corruption and application crashes. With a CVSS score of 5.0, this vulnerability is of medium severity, requiring no authentication or complex attack vectors, and primarily impacting availability. There is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit or ExploitDB, though it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.9.8zeCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* | ||
1.0.0CPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.0:*:*:*:*:*:*:* | ||
1.0.0aCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.0a:*:*:*:*:*:*:* | ||
1.0.0bCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.0b:*:*:*:*:*:*:* | ||
1.0.0cCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.0c:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.