CVE Vulnerabilities

CVE-2015-0290

Published: Mar 19, 2015 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

The multi-block feature in the ssl3_write_bytes function in s3_pkt.c in OpenSSL 1.0.2 before 1.0.2a on 64-bit x86 platforms with AES NI support does not properly handle certain non-blocking I/O cases, which allows remote attackers to cause a denial of service (pointer corruption and application crash) via unspecified vectors.

Affected Software

Name Vendor Start Version End Version
Openssl Openssl 1.0.2 1.0.2
Openssl Openssl 1.0.2 1.0.2
Openssl Openssl 1.0.2 1.0.2
Openssl Openssl 1.0.2 1.0.2

References