CVE-2015-3196
06.12.2015, 20:59
ssl/s3_clnt.c in OpenSSL 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1p, and 1.0.2 before 1.0.2d, when used for a multi-threaded client, writes the PSK identity hint to an incorrect data structure, which allows remote servers to cause a denial of service (race condition and double free) via a crafted ServerKeyExchange message.
Vendor | Product | Version |
---|---|---|
hp | icewall_sso | 10.0 |
hp | icewall_sso_agent_option | 10.0 |
openssl | openssl | 1.0.0 |
openssl | openssl | 1.0.0a:a |
openssl | openssl | 1.0.0b:b |
openssl | openssl | 1.0.0c:c |
openssl | openssl | 1.0.0d:d |
openssl | openssl | 1.0.0e:e |
openssl | openssl | 1.0.0f:f |
openssl | openssl | 1.0.0g:g |
openssl | openssl | 1.0.0h:h |
openssl | openssl | 1.0.0i:i |
openssl | openssl | 1.0.0j:j |
openssl | openssl | 1.0.0k:k |
openssl | openssl | 1.0.0l:l |
openssl | openssl | 1.0.0m:m |
openssl | openssl | 1.0.0n:n |
openssl | openssl | 1.0.0o:o |
openssl | openssl | 1.0.0p:p |
openssl | openssl | 1.0.0q:q |
openssl | openssl | 1.0.0r:r |
openssl | openssl | 1.0.0s:s |
openssl | openssl | 1.0.1 |
openssl | openssl | 1.0.1a:a |
openssl | openssl | 1.0.1b:b |
openssl | openssl | 1.0.1c:c |
openssl | openssl | 1.0.1d:d |
openssl | openssl | 1.0.1e:e |
openssl | openssl | 1.0.1f:f |
openssl | openssl | 1.0.1g:g |
openssl | openssl | 1.0.1h:h |
openssl | openssl | 1.0.1i:i |
openssl | openssl | 1.0.1j:j |
openssl | openssl | 1.0.1k:k |
openssl | openssl | 1.0.1l:l |
openssl | openssl | 1.0.1m:m |
openssl | openssl | 1.0.1n:n |
openssl | openssl | 1.0.1o:o |
oracle | vm_virtualbox | 4.3.0 ≤ 𝑥 ≤ 4.3.35 |
oracle | vm_virtualbox | 5.0.0 ≤ 𝑥 ≤ 5.0.13 |
redhat | enterprise_linux_desktop | 6.0 |
redhat | enterprise_linux_desktop | 7.0 |
redhat | enterprise_linux_server | 6.0 |
redhat | enterprise_linux_server | 7.0 |
redhat | enterprise_linux_server_aus | 7.2 |
redhat | enterprise_linux_server_aus | 7.3 |
redhat | enterprise_linux_server_aus | 7.4 |
redhat | enterprise_linux_server_eus | 6.7 |
redhat | enterprise_linux_server_eus | 7.2 |
redhat | enterprise_linux_server_eus | 7.3 |
redhat | enterprise_linux_server_eus | 7.4 |
redhat | enterprise_linux_server_eus | 7.5 |
redhat | enterprise_linux_server_eus | 7.6 |
redhat | enterprise_linux_server_tus | 7.2 |
redhat | enterprise_linux_server_tus | 7.3 |
redhat | enterprise_linux_server_tus | 7.6 |
redhat | enterprise_linux_workstation | 6.0 |
redhat | enterprise_linux_workstation | 7.0 |
canonical | ubuntu_linux | 12.04 |
canonical | ubuntu_linux | 14.04 |
canonical | ubuntu_linux | 15.04 |
canonical | ubuntu_linux | 15.10 |
debian | debian_linux | 7.0 |
debian | debian_linux | 8.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases