CVE Vulnerabilities

CVE-2015-3216

Published: Jul 07, 2015 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
4.3 LOW
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V3
Ubuntu
MEDIUM

Race condition in a certain Red Hat patch to the PRNG lock implementation in the ssleay_rand_bytes function in OpenSSL, as distributed in openssl-1.0.1e-25.el7 in Red Hat Enterprise Linux (RHEL) 7 and other products, allows remote attackers to cause a denial of service (application crash) by establishing many TLS sessions to a multithreaded server, leading to use of a negative value for a certain length field.

Affected Software

Name Vendor Start Version End Version
Enterprise_linux Redhat 7.0 (including) 7.0 (including)
Red Hat Enterprise Linux 6 RedHat openssl-0:1.0.1e-30.el6_6.11 *
Red Hat Enterprise Linux 7 RedHat openssl-1:1.0.1e-42.ael7b_1.8 *
Text-Only JBCS RedHat *

References