Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2010-5298

Опубликовано: 14 апр. 2014
Источник: ubuntu
Приоритет: low
EPSS Средний
CVSS2: 4

Описание

Race condition in the ssl3_read_bytes function in s3_pkt.c in OpenSSL through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, allows remote attackers to inject data across sessions or cause a denial of service (use-after-free and parsing error) via an SSL connection in a multithreaded environment.

РелизСтатусПримечание
devel

released

1.0.1f-1ubuntu3
esm-infra-legacy/trusty

not-affected

1.0.1f-1ubuntu2.1
lucid

not-affected

code not present
precise

released

1.0.1-4ubuntu5.13
quantal

released

1.0.1c-3ubuntu2.8
saucy

released

1.0.1e-3ubuntu1.3
trusty

released

1.0.1f-1ubuntu2.1
trusty/esm

not-affected

1.0.1f-1ubuntu2.1
upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

not-affected

code not present
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was not-affected [code not present]]
lucid

DNE

precise

not-affected

code not present
quantal

not-affected

code not present
saucy

not-affected

code not present
trusty

not-affected

code not present
trusty/esm

DNE

trusty was not-affected [code not present]
upstream

needs-triage

Показывать по

EPSS

Процентиль: 94%
0.14635
Средний

4 Medium

CVSS2

Связанные уязвимости

redhat
около 11 лет назад

Race condition in the ssl3_read_bytes function in s3_pkt.c in OpenSSL through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, allows remote attackers to inject data across sessions or cause a denial of service (use-after-free and parsing error) via an SSL connection in a multithreaded environment.

nvd
около 11 лет назад

Race condition in the ssl3_read_bytes function in s3_pkt.c in OpenSSL through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, allows remote attackers to inject data across sessions or cause a denial of service (use-after-free and parsing error) via an SSL connection in a multithreaded environment.

debian
около 11 лет назад

Race condition in the ssl3_read_bytes function in s3_pkt.c in OpenSSL ...

github
около 3 лет назад

Race condition in the ssl3_read_bytes function in s3_pkt.c in OpenSSL through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, allows remote attackers to inject data across sessions or cause a denial of service (use-after-free and parsing error) via an SSL connection in a multithreaded environment.

oracle-oval
почти 11 лет назад

ELSA-2014-0679: openssl security update (IMPORTANT)

EPSS

Процентиль: 94%
0.14635
Средний

4 Medium

CVSS2

Уязвимость CVE-2010-5298