CVE-2015-3194 is a denial-of-service vulnerability affecting OpenSSL versions 1.0.1 prior to 1.0.1q and 1.0.2 prior to 1.0.2e, as well as products like Canonical, Debian, and Node.js that incorporate these OpenSSL versions. This flaw, rated High severity (CVSS 7.5), allows a remote attacker to trigger a NULL pointer dereference and application crash by providing a malformed RSA PSS ASN.1 signature lacking a mask generation function parameter. The attack requires no user interaction and has low attack complexity. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. However, the vulnerability has garnered some community discussion and media coverage, indicating awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.1CPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.1:*:*:*:*:*:*:* | ||
1.0.1aCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.1a:*:*:*:*:*:*:* | ||
1.0.1bCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.1b:*:*:*:*:*:*:* | ||
1.0.1cCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.1c:*:*:*:*:*:*:* | ||
1.0.1dCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.1d:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.