CVE-2015-3196

OpenSSL 1.0.0-1.0.0s 1.0.1-1.0.1o 1.0.2-1.0.2c - Denial of Service via PSK Identity Hint Race Condition

Title source: llm
STIX 2.1

Description

ssl/s3_clnt.c in OpenSSL 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1p, and 1.0.2 before 1.0.2d, when used for a multi-threaded client, writes the PSK identity hint to an incorrect data structure, which allows remote servers to cause a denial of service (race condition and double free) via a crafted ServerKeyExchange message.

References (26)

Core 26
Core References
Mailing List, Third Party Advisory vendor-advisory
http://lists.opensuse.org/opensuse-updates/2015-12/msg00071.html
Third Party Advisory, VDB Entry vdb-entry
http://www.securitytracker.com/id/1034294
Third Party Advisory vendor-advisory
http://www.debian.org/security/2015/dsa-3413
Mailing List, Third Party Advisory vendor-advisory
http://lists.opensuse.org/opensuse-updates/2015-12/msg00070.html
Third Party Advisory vendor-advisory
http://rhn.redhat.com/errata/RHSA-2015-2617.html
Third Party Advisory, VDB Entry vdb-entry
http://www.securityfocus.com/bid/78622
Mailing List, Third Party Advisory vendor-advisory
http://marc.info/?l=bugtraq&m=145382583417444&w=2
Third Party Advisory vendor-advisory
http://www.ubuntu.com/usn/USN-2830-1
Third Party Advisory vendor-advisory
http://rhn.redhat.com/errata/RHSA-2016-2957.html

Scores

EPSS 0.0744
EPSS Percentile 91.8%

Details

CWE
CWE-362
Status published
Products (50)
canonical/ubuntu_linux 12.04
canonical/ubuntu_linux 14.04
canonical/ubuntu_linux 15.04
canonical/ubuntu_linux 15.10
debian/debian_linux 7.0
debian/debian_linux 8.0
fedoraproject/fedora 22
hp/icewall_sso 10.0
hp/icewall_sso_agent_option 10.0
openssl/openssl 1.0.0
... and 40 more
Published Dec 06, 2015
Tracked Since Feb 18, 2026