OpenSSL released fixes for five vulnerabilities across supported branches: CVE-2015-3193, an x86_64 BN_mod_exp Montgomery-squaring carry-propagation flaw that can yield incorrect cryptographic results and could aid private-key recovery in Diffie-Hellman/DHE use; CVE-2015-3194, a malformed RSA-PSS certificate-parameter crash; and CVE-2015-3195, an X509_ATTRIBUTE memory leak in PKCS#7 and CMS processing. The advisory also addressed CVE-2015-3196, a PSK identity-hint race condition, and CVE-2015-1794, an anonymous-DH ServerKeyExchange denial-of-service issue.
Organizations were advised to upgrade to OpenSSL 1.0.2e, 1.0.1q, 1.0.0t, or 0.9.8zh as applicable. CVE-2015-3193 affects versions before 1.0.2e on x86_64 systems and is most relevant where DH or DHE cipher suites are enabled; exploitation was considered high complexity. OpenSSL also announced that 1.0.0t and 0.9.8zh would be the final releases for their branches as support for OpenSSL 1.0.0 and 0.9.8 ended.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
OpenSSL publicly disclosed CVE-2015-3193, CVE-2015-3194, CVE-2015-3195, CVE-2015-3196, and CVE-2015-1794, and recommended upgrades including 1.0.2e and 1.0.1q. The advisory noted that CVE-2015-3196, a PSK identity-hint race condition that can lead to double free, had already been fixed in 1.0.2d and 1.0.1p but had not previously appeared in an advisory.
Adam Langley of Google/BoringSSL reported CVE-2015-3195 using libFuzzer. A malformed X509_ATTRIBUTE structure can cause a memory leak when processing PKCS#7 or CMS data from untrusted sources.
Loïc Jonas Etienne of Qnective AG reported CVE-2015-3194 to OpenSSL. An ASN.1 RSA-PSS signature lacking a mask-generation-function parameter can trigger a NULL-pointer dereference during certificate verification.
Hanno Böck reported CVE-2015-3193 to OpenSSL. Incorrect carry propagation in the x86_64 Montgomery squaring procedure can cause BN_mod_exp to produce incorrect results.
Guy Leaver of Cisco reported CVE-2015-1794 to OpenSSL. The flaw allows an anonymous DH ServerKeyExchange with a p value of 0 to cause a client segmentation fault and possible denial of service.
OpenSSL updated its December 3 security advisory to add details of CVE-2015-1794. The anonymous-DH handling flaw had already been fixed in released packages but was omitted from the original advisory text.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.