HIGH
OpenSSL TLS extension parsing race condition
Published Nov 17, 2010
7.6
HIGHCVSS 2.0
EPSS 22.14%
Description
Multiple race conditions in ssl/t1_lib.c in OpenSSL 0.9.8f through 0.9.8o, 1.0.0, and 1.0.0a, when multi-threading and internal caching are enabled on a TLS server, might allow remote attackers to execute arbitrary code via client data that triggers a heap-based buffer overflow, related to (1) the TLS server name extension and (2) elliptic curve cryptography.
Affected products
No data.
OR
- 0.9.8f
- 0.9.8g
- 0.9.8h
- 0.9.8i
- 0.9.8j
- 0.9.8k
- 0.9.8l
- 0.9.8m
- 0.9.8n
- 0.9.8o
- 1.0.0
- 1.0.0a
No data.
Red Hat Enterprise Linux 6
openssl-0:1.0.0-4.el6_0.1
Fixed · RHSA-2010:0888
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | openssl-0:1.0.0-4.el6_0.1 | Fixed | RHSA-2010:0888 |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue does not affect the versions of OpenSSL as shipped with Red Hat Enterprise Linux versions before Enterprise Linux 6.
Weaknesses (2)
References (42)
- http://blogs.sun.com/security/entry/cve_2010_3864_race_condition x_refsource_CONFIRM
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02794777 vendor-advisoryx_refsource_HP
- http://lists.apple.com/archives/security-announce/2011//Jun/msg00000.html vendor-advisoryx_refsource_APPLE
- http://lists.fedoraproject.org/pipermail/package-announce/2010-November/051170.html vendor-advisoryx_refsource_FEDORA
- http://lists.fedoraproject.org/pipermail/package-announce/2010-November/051237.html vendor-advisoryx_refsource_FEDORA
- http://lists.fedoraproject.org/pipermail/package-announce/2010-November/051255.html vendor-advisoryx_refsource_FEDORA
- http://lists.opensuse.org/opensuse-security-announce/2010-11/msg00006.html vendor-advisoryx_refsource_SUSE
- http://marc.info/?l=bugtraq&m=129916880600544&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=130497251507577&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=132828103218869&w=2 vendor-advisoryx_refsource_HP
- http://openssl.org/news/secadv_20101116.txt x_refsource_CONFIRMPatchVendor Advisory
- http://secunia.com/advisories/42241 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/42243 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/42309 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/42336 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/42352 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/42397 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/42413 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/43312 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/44269 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/57353 third-party-advisoryx_refsource_SECUNIA
- http://security.FreeBSD.org/advisories/FreeBSD-SA-10:10.openssl.asc vendor-advisoryx_refsource_FREEBSD
- http://securitytracker.com/id?1024743 vdb-entryx_refsource_SECTRACKPatch
- http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.668793 vendor-advisoryx_refsource_SLACKWARE
- http://support.apple.com/kb/HT4723 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004564 x_refsource_CONFIRM
- http://www.adobe.com/support/security/bulletins/apsb11-11.html x_refsource_CONFIRM
- http://www.debian.org/security/2010/dsa-2125 vendor-advisoryx_refsource_DEBIAN
- http://www.kb.cert.org/vuls/id/737740 third-party-advisoryx_refsource_CERT-VNUS Government Resource
- http://www.securityfocus.com/archive/1/516397/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.vmware.com/security/advisories/VMSA-2011-0003.html x_refsource_CONFIRM
- http://www.vupen.com/english/advisories/2010/3041 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2010/3077 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2010/3097 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2010/3121 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2010-3864 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=649304 x_refsource_CONFIRMPatchIssue Tracking
- https://lists.balabit.com/pipermail/syslog-ng-announce/2011-January/000101.html mailing-listx_refsource_MLIST
- https://lists.balabit.com/pipermail/syslog-ng-announce/2011-January/000102.html mailing-listx_refsource_MLIST
- https://nvd.nist.gov/vuln/detail/CVE-2010-3864
- https://rhn.redhat.com/errata/RHSA-2010-0888.html vendor-advisoryx_refsource_REDHAT
- https://www.cve.org/CVERecord?id=CVE-2010-3864
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Nov 17, 2010
Updated Aug 7, 2024
Reserved Oct 8, 2010
Link CVE-2010-3864
CISA Vulnrichment
Updated n/a