PT-2010-1090 · Openssl · Openssl

Georgi Guninski

·

Published

2010-08-17

·

Updated

2024-06-15

·

CVE-2010-2939

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions OpenSSL versions 0.9.7 through 1.0.0a OpenSSL versions prior to 1.0.0e
Description A double free vulnerability in the ssl3 get key exchange function in the OpenSSL client allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via a crafted private key with an invalid prime. This issue may also be referred to as a use-after-free issue. The vulnerability can be exploited remotely and may lead to a violation of confidentiality, integrity, and availability of protected information.
Recommendations For OpenSSL versions 0.9.7 through 1.0.0a, update to a version later than 1.0.0a to resolve the issue. For OpenSSL versions prior to 1.0.0e, update to version 1.0.0e or later to resolve the issue. As a temporary workaround, consider restricting the use of ECDH in the OpenSSL client until a patch is available.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-09418
CVE-2010-2939
DSA-2100-1
OPENSUSE-SU-2024:10271-1
OPENSUSE-SU-2024:10529-1
OPENSUSE-SU-2024:11127-1
SUSE-FU-2022:0445-1
SUSE-SU-2015:1184-1
SUSE-SU-403

Affected Products

Openssl