Back

MEDIUM

openssl: Crash in ssleay_rand_bytes due to locking regression

Published Jul 7, 2015

Description

Race condition in a certain Red Hat patch to the PRNG lock implementation in the ssleay_rand_bytes function in OpenSSL, as distributed in openssl-1.0.1e-25.el7 in Red Hat Enterprise Linux (RHEL) 7 and other products, allows remote attackers to cause a denial of service (application crash) by establishing many TLS sessions to a multithreaded server, leading to use of a negative value for a certain length field.

Affected products

Remediation

Red Hat statement

This issue does not affect the version of OpenSSL package as shipped with Red Hat Enterprise Linux 5.

Metrics

References (14)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jul 7, 2015
Updated Aug 6, 2024
Reserved Apr 10, 2015
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date May 28, 2015