Race condition in a certain Red Hat patch to the PRNG lock implementation in the ssleay_rand_bytes function in OpenSSL, as distributed in openssl-1.0.1e-25.el7 in Red Hat Enterprise Linux (RHEL) 7 and other products, allows remote attackers to cause a denial of service (application crash) by establishing many TLS sessions to a multithreaded server, leading to use of a negative value for a certain length field.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Enterprise_linux | Redhat | 7.0 (including) | 7.0 (including) |
Red Hat Enterprise Linux 6 | RedHat | openssl-0:1.0.1e-30.el6_6.11 | * |
Red Hat Enterprise Linux 7 | RedHat | openssl-1:1.0.1e-42.ael7b_1.8 | * |
Text-Only JBCS | RedHat | * |