PT-2015-1695 · Openssl+3 · Openssl+3

John Sullivan

·

Published

2014-10-24

·

Updated

2018-01-05

·

CVE-2015-3216

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions OpenSSL versions 1.0.1e-25.el7
Description The issue is related to a race condition in the PRNG lock implementation in the ssleay rand bytes function in OpenSSL, which can cause a denial of service (application crash) when many TLS sessions are established to a multithreaded server. This can lead to the use of a negative value for a certain length field. Additionally, the vulnerability is associated with a buffer overflow in dynamic memory caused by an integer overflow, allowing a remote attacker to cause a denial of service by establishing multiple TLS sessions.
Recommendations For OpenSSL version 1.0.1e-25.el7, consider restricting access to the ssleay rand bytes function as a temporary workaround until a patch is available. Avoid using the function in multithreaded servers to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-11041
CESA-2015_1115
CVE-2015-3216
OPENSUSE-SU-2015_1139-1
RHSA-2015:1115
RHSA-2015_1115
SUSE-SU-2015:1143-1
SUSE-SU-2015:1150-1
SUSE-SU-403

Affected Products

Centos
Openssl
Red Hat
Suse