Lucene search

K
opensslOpenSSLOPENSSL:CVE-2015-1791
HistoryJun 02, 2015 - 12:00 a.m.

Vulnerability in OpenSSL - Race condition handling NewSessionTicket

2015-06-0200:00:00
www.openssl-library.org
44

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

6.6

Confidence

High

EPSS

0.394

Percentile

97.3%

If a NewSessionTicket is received by a multi-threaded client when attempting to reuse a previous ticket then a race condition can occur potentially leading to a double free of the ticket data.

Found by Emilia Käsper (OpenSSL).

Affected configurations

Vulners
Node
opensslopensslRange1.0.21.0.2b
OR
opensslopensslRange1.0.11.0.1n
OR
opensslopensslRange1.0.01.0.0s
OR
opensslopensslRange0.9.80.9.8zg
VendorProductVersionCPE
opensslopenssl*cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

6.6

Confidence

High

EPSS

0.394

Percentile

97.3%