RULE(RULE ID:709879)

Rule General Information
Release Date: 2015-09-16
Rule Name: PROTOCOL-SSL Openssl Asn1_type_cmp Denial of Service Vulnerability -1 (CVE-2015-0286)
Severity:
CVE ID:
Rule Protection Details
Description: The ASN1_TYPE_cmp function in crypto/asn1/a_type.c in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a does not properly perform boolean-type comparisons, which allows remote attackers to cause a denial of service (invalid read operation and application crash) via a crafted X.509 certificate to an endpoint that uses the certificate-verification feature.
Impact: An attacker can launch a denial of service attack by exploiting the vulnerability successfully.
Affected OS: Windows, Solaris, Other Unix, FreeBSD, Linux
Reference: SecurityFocusBID:73225
SecurityTrackerID:1031929
Solutions
More advisories have been published on the website, please visit for more suggestions:
https://www.openssl.org/news/secadv_20150319.txt