PT-2011-1151 · Openssl+2 · Openssl+2

Vincent Danen

·

Publicado

2011-09-06

·

Atualizado

2014-10-24

·

CVE-2011-3210

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions OpenSSL versions 0.9.8 through 0.9.8r and 1.0.x before 1.0.0e Gentoo Linux (affected versions not specified)
Description The issue affects the ephemeral ECDH ciphersuite functionality, which does not ensure thread safety during processing of handshake messages from clients. This can be exploited remotely, potentially leading to a denial of service (daemon crash) via out-of-order messages that violate the TLS protocol. The exploitation of these vulnerabilities may compromise the confidentiality, integrity, and availability of protected information.
Recommendations For OpenSSL versions 0.9.8 through 0.9.8r, update to a version that ensures thread safety during handshake message processing. For OpenSSL versions 1.0.x before 1.0.0e, update to version 1.0.0e or later to address the issue. As a temporary workaround, consider restricting access to the ephemeral ECDH ciphersuite functionality until a patch is available.

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-09418
CVE-2011-3210
HPSBUX02734
OPENSUSE-SU-2024:10271-1
OPENSUSE-SU-2024:10529-1
SUSE-FU-2022:0445-1
SUSE-SU-2015:1184-1
SUSE-SU-403

Produtos afetados

Gentoo Linux
Hp-Ux
Openssl