Pre-Auth RCE Risk: OpenSSL Patches High-Severity Stack Overflow (CVE-2025-15467)
ID: 4e5b0e2c-9b35-5bd7-9dfa-3d0368b15982
STIX ID: report--4e5b0e2c-9b35-5bd7-9dfa-3d0368b15982
Feed Name: securityonline.info
Threat Score
**OpenSSL security update addressing multiple vulnerabilities:** The advisory details a high-severity stack buffer overflow in CMS AuthEnvelopedData processing (CVE-2025-15467) that can be triggered without authentication and may allow remote code execution or denial-of-service, a moderate PKCS#12 PBMAC1 validation issue (CVE-2025-11187), and several low-severity flaws; maintainers provide specific patched OpenSSL versions for affected branches.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
