CVE-2015-3194: Canonical Ubuntu Linux
High severity, CVSS 7.5. EPSS: 44% chance of exploitation in the next 30 days.
crypto/rsa/rsa_ameth.c in OpenSSL 1.0.1 before 1.0.1q and 1.0.2 before 1.0.2e allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an RSA PSS ASN.1 signature that lacks a mask generation function parameter.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.04 only; version 15.10 only
- Debian Debian Linux: version 7.0 only; version 8.0 only
- Node.js Node.js: from 0.10.0, before 0.10.41 (fixed in 0.10.41); from 0.12.0, before 0.12.9 (fixed in 0.12.9); from 4.0.0, before 4.2.3 (fixed in 4.2.3); from 5.0.0, before 5.1.1 (fixed in 5.1.1)
- OpenSSL OpenSSL: version 1.0.1 only; version 1.0.1a only; version 1.0.1b only; version 1.0.1c only; version 1.0.1d only; version 1.0.1e only; …
Published 2015-12-06. Last modified 2026-06-17.