Vulnerability Bulletins

AIX OpenSSL Denial of Service (memory corruption and application crash) via a malformed Elliptic Curve (EC) private-key file that is improperly handled during import

   
Affected software IBM
 
1. CVE-2015-0209 OpenSSL could allow remote attackers to cause a denial of service (memory corruption and application crash) via a malformed Elliptic Curve (EC) private-key file that is improperly handled during import 2. CVE-2015-0286 OpenSSL could allow remote attackers to cause a denial of service (invalid read operation and application crash) via a crafted X.509 certificate to an endpoint that uses the certificate-verification feature 3. CVE-2015-0287 OpenSSL could allow remote attackers

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/aix_openssl_denial_of_service_memory_corruption_and_application_crash_via_a_malformed_elliptic_curve_ec_private_key_file_that_is_improperly_handled_during_import?lang=en_us