Uploaded image for project: 'JBoss Web Server'
  1. JBoss Web Server
  2. JWS-223

CVE-2015-0286 openssl: invalid pointer use in ASN1_TYPE_cmp() [jbews-3.0.0]

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Duplicate
    • Icon: Major Major
    • JWS 3.0.3 DR3
    • JWS 3.0.0 GA
    • openssl
    • None
    • Release Notes
    • Not Yet Documented

      The function ASN1_TYPE_cmp will crash with an invalid read if an attempt is made to compare ASN.1 boolean types. Since ASN1_TYPE_cmp is used to check certificate signature algorithm consistency this can be used to crash any certificate verification operation and exploited in a denial of service attack. Any application which performs certificate verification is vulnerable, including OpenSSL clients and servers which enable client authentication.

            weli@redhat.com Weinan Li
            rhn-support-twalsh Tim Walsh
            Michal Karm Michal Karm
            Votes:
            0 Vote for this issue
            Watchers:
            4 Start watching this issue

              Created:
              Updated:
              Resolved: