CVE-2015-0292: OpenSSL

High severity, CVSS 7.5. EPSS: 44.5% chance of exploitation in the next 30 days.

Integer underflow in the EVP_DecodeUpdate function in crypto/evp/encode.c in the base64-decoding implementation in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via crafted base64 data that triggers a buffer overflow.

Affected products

  • OpenSSL OpenSSL: up to and including 0.9.8z; version 1.0.0 only; version 1.0.0a only; version 1.0.0b only; version 1.0.0c only; version 1.0.0d only; …

Published 2015-03-19. Last modified 2026-06-17.