CVE Database
/

CVE-2015-1791

Back to search

CVE-2015-1791

Published: Jun 12, 2015

Modified: Aug 6, 2024

PUBLISHED

Description

Race condition in the ssl3_get_new_session_ticket function in ssl/s3_clnt.c in OpenSSL before 0.9.8zg, 1.0.0 before 1.0.0s, 1.0.1 before 1.0.1n, and 1.0.2 before 1.0.2b, when used for a multi-threaded client, allows remote attackers to cause a denial of service (double free and application crash) or possibly have unspecified other impact by providing a NewSessionTicket during an attempt to reuse a ticket that had been obtained earlier.

VendorProductVersions

n/a

n/a

affected
n/a

References

SUSE-SU-2015:1184
vendor-advisory
SSRT102180
vendor-advisory
DSA-3287
vendor-advisory
SUSE-SU-2015:1150
vendor-advisory
HPSBMU03409
vendor-advisory
75161
vdb-entry
RHSA-2015:1115
vendor-advisory
1032479
vdb-entry
SUSE-SU-2015:1182
vendor-advisory
SUSE-SU-2015:1143
vendor-advisory
openSUSE-SU-2016:0640
vendor-advisory
FEDORA-2015-10108
vendor-advisory
APPLE-SA-2015-08-13-2
vendor-advisory
USN-2639-1
vendor-advisory
GLSA-201506-02
vendor-advisory
91787
vdb-entry
HPSBUX03388
vendor-advisory
FEDORA-2015-10047
vendor-advisory
SUSE-SU-2015:1185
vendor-advisory
openSUSE-SU-2015:1139
vendor-advisory
NetBSD-SA2015-008
vendor-advisory

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now