SSL: OpenSSL RSA PSS Absent Mask Generation Parameter Denial of Service
This signature detects attempts to exploit a known vulnerability against OpenSSL. The vulnerability is due to a NULL pointer dereference when an OpenSSL application receives and processes a crafted certificate containing an invalid RSA PSS parameter. A successful attack can result in a denial-of-service condition.
Extended Description
crypto/rsa/rsa_ameth.c in OpenSSL 1.0.1 before 1.0.1q and 1.0.2 before 1.0.2e allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an RSA PSS ASN.1 signature that lacks a mask generation function parameter.
Affected Products
Nodejs node.js
References
CVE: CVE-2015-3194
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Nodejs
Debian
Openssl
Canonical
5.0