Back to search
CVE-2015-3196
Published: Dec 6, 2015
Modified: Aug 6, 2024
PUBLISHED
Description
ssl/s3_clnt.c in OpenSSL 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1p, and 1.0.2 before 1.0.2d, when used for a multi-threaded client, writes the PSK identity hint to an incorrect data structure, which allows remote servers to cause a denial of service (race condition and double free) via a crafted ServerKeyExchange message.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
openSUSE-SU-2015:2288
vendor-advisory
RHSA-2015:2617
vendor-advisory
SSA:2015-349-04
vendor-advisory
78622
vdb-entry
HPSBGN03536
vendor-advisory
USN-2830-1
vendor-advisory
openSUSE-SU-2015:2289
vendor-advisory
FEDORA-2015-d87d60b9a9
vendor-advisory
RHSA-2016:2957
vendor-advisory
1034294
vdb-entry
DSA-3413
vendor-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now