CVE-2010-3864

OpenSSL 0.9.8f-0.9.8o, 1.0.0, 1.0.0a - Remote Code Execution via TLS Server Name Extension Race Condition

Title source: llm
STIX 2.1

Description

Multiple race conditions in ssl/t1_lib.c in OpenSSL 0.9.8f through 0.9.8o, 1.0.0, and 1.0.0a, when multi-threading and internal caching are enabled on a TLS server, might allow remote attackers to execute arbitrary code via client data that triggers a heap-based buffer overflow, related to (1) the TLS server name extension and (2) elliptic curve cryptography.

References (39)

Core 39
Core References
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2010-November/051170.html
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=132828103218869&w=2
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/3041
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT4723
Patch vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1024743
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/42413
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2010-November/051255.html
Patch, Vendor Advisory x_refsource_confirm
http://openssl.org/news/secadv_20101116.txt
Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2011//Jun/msg00000.html
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2010-November/051237.html
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/737740
Vendor Advisory vendor-advisory x_refsource_redhat
https://rhn.redhat.com/errata/RHSA-2010-0888.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/42397
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=130497251507577&w=2
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/42241
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=129916880600544&w=2
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/57353
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/3097
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/42336
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/42309
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/3077
Various Sources vendor-advisory x_refsource_freebsd
http://security.FreeBSD.org/advisories/FreeBSD-SA-10:10.openssl.asc
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/44269
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/43312
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/42243
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/3121
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/42352
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/516397/100/0/threaded
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2010/dsa-2125

Scores

EPSS 0.0482
EPSS Percentile 89.6%

Details

CWE
CWE-362
Status published
Products (12)
openssl/openssl 0.9.8f
openssl/openssl 0.9.8g
openssl/openssl 0.9.8h
openssl/openssl 0.9.8i
openssl/openssl 0.9.8j
openssl/openssl 0.9.8k
openssl/openssl 0.9.8l
openssl/openssl 0.9.8m
openssl/openssl 0.9.8n
openssl/openssl 0.9.8o
... and 2 more
Published Nov 17, 2010
Tracked Since Feb 18, 2026