PT-2010-5627 · Openssl+2 · Openssl+6

Published

1970-01-01

·

Updated

2024-06-15

·

CVE-2010-3864

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions OpenSSL versions 0.9.8f through 0.9.8o OpenSSL versions 1.0.0 and 1.0.0a libssl-dev (affected versions not specified) libssl0.9.8-dbg (affected versions not specified) libssl0.9.8 (affected versions not specified) libcrypto0.9.8-udeb (affected versions not specified) openssl (affected versions prior to 1.0.0e)
Description The issue involves multiple vulnerabilities in the OpenSSL package, which can lead to a breach of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. The vulnerabilities are related to multiple race conditions in ssl/t1 lib.c when multi-threading and internal caching are enabled on a TLS server. This might allow remote attackers to execute arbitrary code via client data that triggers a heap-based buffer overflow, related to the TLS server name extension and elliptic curve cryptography.
Recommendations For OpenSSL versions 0.9.8f through 0.9.8o, update to a version later than 0.9.8o. For OpenSSL versions 1.0.0 and 1.0.0a, update to a version later than 1.0.0a. For libssl-dev, libssl0.9.8-dbg, libssl0.9.8, and libcrypto0.9.8-udeb, there is no information about a newer version that contains a fix for this vulnerability. For openssl (Gentoo Linux), update to a version 1.0.0e or later.

RCE

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-01377
BDU:2015-01465
BDU:2015-01467
BDU:2015-01468
BDU:2015-09418
CVE-2010-3864
DSA-2125-1
HPSBUX02638
OPENSUSE-SU-2024:10271-1
OPENSUSE-SU-2024:10289-1
OPENSUSE-SU-2024:10529-1
OPENSUSE-SU-2024:11127-1
RHSA-2010:0888
RHSA-2010_0888
SUSE-FU-2022:0445-1
SUSE-SU-2015:1184-1
SUSE-SU-403

Affected Products

Hp-Ux
Openssl
Red Hat
Libcrypto0.9.8-Udeb
Libssl-Dev
Libssl0.9.8
Libssl0.9.8-Dbg