PT-2011-1151 · Openssl+2 · Openssl+2

Vincent Danen

·

Published

2011-09-06

·

Updated

2014-10-24

·

CVE-2011-3210

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions OpenSSL versions 0.9.8 through 0.9.8r and 1.0.x before 1.0.0e Gentoo Linux (affected versions not specified)
Description The issue affects the ephemeral ECDH ciphersuite functionality, which does not ensure thread safety during processing of handshake messages from clients. This can be exploited remotely, potentially leading to a denial of service (daemon crash) via out-of-order messages that violate the TLS protocol. The exploitation of these vulnerabilities may compromise the confidentiality, integrity, and availability of protected information.
Recommendations For OpenSSL versions 0.9.8 through 0.9.8r, update to a version that ensures thread safety during handshake message processing. For OpenSSL versions 1.0.x before 1.0.0e, update to version 1.0.0e or later to address the issue. As a temporary workaround, consider restricting access to the ephemeral ECDH ciphersuite functionality until a patch is available.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-09418
CVE-2011-3210
HPSBUX02734
OPENSUSE-SU-2024:10271-1
OPENSUSE-SU-2024:10529-1
SUSE-FU-2022:0445-1
SUSE-SU-2015:1184-1
SUSE-SU-403

Affected Products

Gentoo Linux
Hp-Ux
Openssl