CVE-2015-5333: OpenBSD Libressl

High severity, CVSS 7.5. EPSS: 2% chance of exploitation in the next 30 days.

Memory leak in the OBJ_obj2txt function in LibreSSL before 2.3.1 allows remote attackers to cause a denial of service (memory consumption) via a large number of ASN.1 object identifiers in X.509 certificates.

Affected products

  • OpenBSD Libressl: before 2.3.1 (fixed in 2.3.1)
  • Opensuse Opensuse: version 13.2 only

Published 2020-01-23. Last modified 2026-06-17.