Lucene search

K
cve[email protected]CVE-2010-3083
HistoryOct 12, 2010 - 9:00 p.m.

CVE-2010-3083

2010-10-1221:00:02
web.nvd.nist.gov
30
2
cve-2010-3083
apache qpid
red hat enterprise mrg
ssl
denial of service
security vulnerability

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

6.8 Medium

AI Score

Confidence

High

0.007 Low

EPSS

Percentile

81.0%

sys/ssl/SslSocket.cpp in qpidd in Apache Qpid, as used in Red Hat Enterprise MRG before 1.2.2 and other products, when SSL is enabled, allows remote attackers to cause a denial of service (daemon outage) by connecting to the SSL port but not participating in an SSL handshake.

Affected configurations

NVD
Node
apacheqpidMatch0.5
OR
apacheqpidMatch0.6
AND
redhatenterprise_mrgRange1.2
OR
redhatenterprise_mrgMatch1.0
OR
redhatenterprise_mrgMatch1.0.1
OR
redhatenterprise_mrgMatch1.0.2
OR
redhatenterprise_mrgMatch1.0.3
OR
redhatenterprise_mrgMatch1.1.1
OR
redhatenterprise_mrgMatch1.1.2

Social References

More

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

6.8 Medium

AI Score

Confidence

High

0.007 Low

EPSS

Percentile

81.0%

Related for CVE-2010-3083