CVE-2010-5298
Race condition in the ssl3_read_bytes function in s3_pkt.c in OpenSSL through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, allows remote attackers to inject data across sessions or cause a denial of service (use-after-free and parsing error) via an…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 34.1%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Race condition in the ssl3_read_bytes function in s3_pkt.c in OpenSSL through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, allows remote attackers to inject data across sessions or cause a denial of service (use-after-free and parsing error) via an SSL connection in a multithreaded environment.
- CVSS 2.0
- 4.0 MEDIUMAV:N/AC:H/Au:N/C:N/I:P/A:P
- EPSS
- 34.13% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-362
- Affected
- openssl/openssl · mariadb/mariadb · fedoraproject/fedora · suse/linux enterprise desktop · suse/linux enterprise server · suse/linux enterprise software development kit · suse/linux enterprise workstation extension
- Source
- cve@mitre.org
References
- http://advisories.mageia.org/MGASA-2014-0187.htmlThird Party Advisory
- http://ftp.openbsd.org/pub/OpenBSD/patches/5.5/common/004_openssl.patch.sigPatch, Third Party Advisory
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10629Third Party Advisory
- http://kb.juniper.net/InfoCenter/index?page=content&id=KB29195Permissions Required
- http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136470.htmlMailing List, Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136473.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00016.htmlMailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=140389274407904&w=2Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=140389355508263&w=2Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=140431828824371&w=2Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=140448122410568&w=2Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=140544599631400&w=2Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=140621259019789&w=2Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=140752315422991&w=2Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=140904544427729&w=2Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=141658880509699&w=2Mailing List, Third Party Advisory
- http://openwall.com/lists/oss-security/2014/04/13/1Mailing List, Patch
- http://seclists.org/fulldisclosure/2014/Dec/23Mailing List, Third Party Advisory
- http://secunia.com/advisories/58337Not Applicable
- http://secunia.com/advisories/58713Not Applicable
- http://secunia.com/advisories/58939Not Applicable
- http://secunia.com/advisories/58977Not Applicable
- http://secunia.com/advisories/59162Not Applicable
- http://secunia.com/advisories/59287Not Applicable
- http://secunia.com/advisories/59300Not Applicable
- http://secunia.com/advisories/59301Not Applicable
- http://secunia.com/advisories/59342Not Applicable
- http://secunia.com/advisories/59413Not Applicable
- http://secunia.com/advisories/59437Not Applicable
- http://secunia.com/advisories/59438Not Applicable
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.