PT-2010-1087 · Openssl+1 · Openssl+1

Published

2010-03-26

·

Updated

2024-06-15

·

CVE-2010-0740

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions OpenSSL versions 0.9.8f through 0.9.8m
Description The issue allows remote attackers to cause a denial of service (crash) via a malformed record in a TLS connection that triggers a NULL pointer dereference, related to the minor version number. This can be exploited to disrupt the confidentiality, integrity, and availability of protected information. The exploitation can be carried out remotely.
Recommendations For OpenSSL versions 0.9.8f through 0.9.8m, consider updating to a version newer than 0.9.8m to resolve the issue. As a temporary workaround, consider restricting access to TLS connections to minimize the risk of exploitation. Avoid using the ssl3 get record function in the affected OpenSSL versions until a patch is available.

Exploit

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-09418
CVE-2010-0740
HPSBUX02517
HPSBUX02531
OPENSUSE-SU-2024:10271-1
OPENSUSE-SU-2024:10529-1
OPENSUSE-SU-2024:11127-1
SUSE-FU-2022:0445-1

Affected Products

Hp-Ux
Openssl