PT-2015-1695 · Openssl+3 · Openssl+3

John Sullivan

·

Publicado

2014-10-24

·

Atualizado

2018-01-05

·

CVE-2015-3216

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions OpenSSL versions 1.0.1e-25.el7
Description The issue is related to a race condition in the PRNG lock implementation in the ssleay rand bytes function in OpenSSL, which can cause a denial of service (application crash) when many TLS sessions are established to a multithreaded server. This can lead to the use of a negative value for a certain length field. Additionally, the vulnerability is associated with a buffer overflow in dynamic memory caused by an integer overflow, allowing a remote attacker to cause a denial of service by establishing multiple TLS sessions.
Recommendations For OpenSSL version 1.0.1e-25.el7, consider restricting access to the ssleay rand bytes function as a temporary workaround until a patch is available. Avoid using the function in multithreaded servers to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Race Condition

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-11041
CESA-2015_1115
CVE-2015-3216
OPENSUSE-SU-2015_1139-1
RHSA-2015:1115
RHSA-2015_1115
SUSE-SU-2015:1143-1
SUSE-SU-2015:1150-1
SUSE-SU-403

Produtos afetados

Centos
Openssl
Red Hat
Suse