Memory leak in the OBJ_obj2txt function in LibreSSL before 2.3.1 allows remote attackers to cause a denial of service (memory consumption) via a large number of ASN.1 object identifiers in X.509 certificates.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Openssh | — | Apply OS X security update 2016-002Upgrade macOS to the latest version | Mar 29, 2016 | Mar 29, 2016 |
| Freebsd | — | Upgrade libressl | Dec 10, 2025 | Oct 16, 2015 |
| Suse | — | Upgrade libssl37-32bitUpgrade libressl-debuginfoUpgrade libssl37Upgrade libcrypto36-32bitUpgrade libressl-debugsourceUpgrade libressl-devel-docUpgrade libtls9-32bitUpgrade libcrypto36-debuginfoUpgrade libressl-devel-32bitUpgrade libssl37-debuginfo-32bitUpgrade libresslUpgrade libressl-develUpgrade libcrypto36Upgrade libtls9-debuginfo-32bitUpgrade libtls9-debuginfoUpgrade libcrypto36-debuginfo-32bitUpgrade libtls9Upgrade libssl37-debuginfo | Dec 18, 2015 | Oct 27, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub