Lucene search

K
ubuntucveUbuntu.comUB:CVE-2015-1791
HistoryJun 02, 2015 - 12:00 a.m.

CVE-2015-1791

2015-06-0200:00:00
ubuntu.com
ubuntu.com
28

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

0.394 Low

EPSS

Percentile

97.3%

Race condition in the ssl3_get_new_session_ticket function in ssl/s3_clnt.c
in OpenSSL before 0.9.8zg, 1.0.0 before 1.0.0s, 1.0.1 before 1.0.1n, and
1.0.2 before 1.0.2b, when used for a multi-threaded client, allows remote
attackers to cause a denial of service (double free and application crash)
or possibly have unspecified other impact by providing a NewSessionTicket
during an attempt to reuse a ticket that had been obtained earlier.

OSVersionArchitecturePackageVersionFilename
ubuntu17.10noarchopenssl< 1.0.2c-1ubuntu1UNKNOWN
ubuntu18.04noarchopenssl< 1.0.2c-1ubuntu1UNKNOWN
ubuntu18.10noarchopenssl< 1.0.2c-1ubuntu1UNKNOWN
ubuntu19.04noarchopenssl< 1.0.2c-1ubuntu1UNKNOWN
ubuntu12.04noarchopenssl< 1.0.1-4ubuntu5.31UNKNOWN
ubuntu14.04noarchopenssl< 1.0.1f-1ubuntu2.15UNKNOWN
ubuntu14.10noarchopenssl< 1.0.1f-1ubuntu9.8UNKNOWN
ubuntu15.04noarchopenssl< 1.0.1f-1ubuntu11.4UNKNOWN
ubuntu15.10noarchopenssl< 1.0.2c-1ubuntu1UNKNOWN
ubuntu16.04noarchopenssl< 1.0.2c-1ubuntu1UNKNOWN
Rows per page:
1-10 of 121

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

0.394 Low

EPSS

Percentile

97.3%