Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2015-3196

Опубликовано: 06 дек. 2015
Источник: ubuntu
Приоритет: low
CVSS2: 4.3

Описание

ssl/s3_clnt.c in OpenSSL 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1p, and 1.0.2 before 1.0.2d, when used for a multi-threaded client, writes the PSK identity hint to an incorrect data structure, which allows remote servers to cause a denial of service (race condition and double free) via a crafted ServerKeyExchange message.

РелизСтатусПримечание
devel

not-affected

1.0.2d-0ubuntu2
esm-infra-legacy/trusty

not-affected

1.0.1f-1ubuntu2.16
precise

released

1.0.1-4ubuntu5.32
trusty

released

1.0.1f-1ubuntu2.16
trusty/esm

not-affected

1.0.1f-1ubuntu2.16
upstream

released

1.0.2d,1.0.1p
vivid

released

1.0.1f-1ubuntu11.5
vivid/stable-phone-overlay

released

1.0.1f-1ubuntu11.5
vivid/ubuntu-core

released

1.0.1f-1ubuntu11.5
wily

not-affected

1.0.2d-0ubuntu1

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was not-affected]
precise

not-affected

trusty

not-affected

trusty/esm

DNE

trusty was not-affected
upstream

not-affected

vivid

not-affected

vivid/stable-phone-overlay

DNE

vivid/ubuntu-core

DNE

wily

DNE

Показывать по

4.3 Medium

CVSS2

Связанные уязвимости

redhat
больше 9 лет назад

ssl/s3_clnt.c in OpenSSL 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1p, and 1.0.2 before 1.0.2d, when used for a multi-threaded client, writes the PSK identity hint to an incorrect data structure, which allows remote servers to cause a denial of service (race condition and double free) via a crafted ServerKeyExchange message.

nvd
больше 9 лет назад

ssl/s3_clnt.c in OpenSSL 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1p, and 1.0.2 before 1.0.2d, when used for a multi-threaded client, writes the PSK identity hint to an incorrect data structure, which allows remote servers to cause a denial of service (race condition and double free) via a crafted ServerKeyExchange message.

debian
больше 9 лет назад

ssl/s3_clnt.c in OpenSSL 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1p, and ...

github
около 3 лет назад

ssl/s3_clnt.c in OpenSSL 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1p, and 1.0.2 before 1.0.2d, when used for a multi-threaded client, writes the PSK identity hint to an incorrect data structure, which allows remote servers to cause a denial of service (race condition and double free) via a crafted ServerKeyExchange message.

fstec
больше 9 лет назад

Уязвимость библиотеки OpenSSL, позволяющая нарушителю вызвать отказ в обслуживании

4.3 Medium

CVSS2