Lucene search

K
cveMitreCVE-2010-5298
HistoryApr 14, 2014 - 10:38 p.m.

CVE-2010-5298

2014-04-1422:38:08
CWE-362
mitre
web.nvd.nist.gov
107
2
cve-2010-5298
ssl
ssl3_read_bytes
openssl
denial of service
use-after-free
parsing error
multithreaded environment

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:N/I:P/A:P

AI Score

7

Confidence

High

EPSS

0.029

Percentile

90.8%

Race condition in the ssl3_read_bytes function in s3_pkt.c in OpenSSL through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, allows remote attackers to inject data across sessions or cause a denial of service (use-after-free and parsing error) via an SSL connection in a multithreaded environment.

Affected configurations

Nvd
Node
opensslopensslRange1.0.1g
Node
mariadbmariadbRange10.0.010.0.13
Node
fedoraprojectfedoraMatch19
OR
fedoraprojectfedoraMatch20
Node
suselinux_enterprise_desktopMatch12-
OR
suselinux_enterprise_serverMatch12-
OR
suselinux_enterprise_software_development_kitMatch12-
OR
suselinux_enterprise_workstation_extensionMatch12-
VendorProductVersionCPE
opensslopenssl*cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
mariadbmariadb*cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*
fedoraprojectfedora19cpe:2.3:o:fedoraproject:fedora:19:*:*:*:*:*:*:*
fedoraprojectfedora20cpe:2.3:o:fedoraproject:fedora:20:*:*:*:*:*:*:*
suselinux_enterprise_desktop12cpe:2.3:o:suse:linux_enterprise_desktop:12:-:*:*:*:*:*:*
suselinux_enterprise_server12cpe:2.3:o:suse:linux_enterprise_server:12:-:*:*:*:*:*:*
suselinux_enterprise_software_development_kit12cpe:2.3:o:suse:linux_enterprise_software_development_kit:12:-:*:*:*:*:*:*
suselinux_enterprise_workstation_extension12cpe:2.3:o:suse:linux_enterprise_workstation_extension:12:-:*:*:*:*:*:*

References

Social References

More

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:N/I:P/A:P

AI Score

7

Confidence

High

EPSS

0.029

Percentile

90.8%