CVE-2015-3196

CWE-362Race ConditionCWE-39911 documents10 sources
Severity
4.3MEDIUM
EPSS
7.4%
top 8.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 6
Latest updateMay 14

Description

ssl/s3_clnt.c in OpenSSL 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1p, and 1.0.2 before 1.0.2d, when used for a multi-threaded client, writes the PSK identity hint to an incorrect data structure, which allows remote servers to cause a denial of service (race condition and double free) via a crafted ServerKeyExchange message.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages8 packages

Debianopenssl< 1.0.2d-1+3
NVDopenssl/openssl36 versions+35
NVDoracle/vm_virtualbox4.3.04.3.35+1
NVDhp/icewall_sso10.0

Also affects: Debian Linux 7.0, 8.0, Fedora 22, Ubuntu Linux 12.04, 14.04, 15.04, 15.10, Enterprise Linux 7.2, 7.3, 7.4, 6.7, 7.5, 7.6

Patches

🔴Vulnerability Details

3
GHSA
GHSA-wj5w-hq6m-54g7: ssl/s3_clnt2022-05-14
CVEList
CVE-2015-3196: ssl/s3_clnt2015-12-06
OSV
CVE-2015-3196: ssl/s3_clnt2015-12-06

📋Vendor Advisories

5
Ubuntu
OpenSSL vulnerabilities2015-12-07
BSD
FreeBSD-SA-15:26.openssl: Multiple OpenSSL vulnerabilities2015-12-06
Cisco
Multiple Vulnerabilities in OpenSSL (December 2015) Affecting Cisco Products2015-12-04
Red Hat
OpenSSL: Race condition handling PSK identify hint2015-12-03
Debian
CVE-2015-3196: openssl - ssl/s3_clnt.c in OpenSSL 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1p, and 1.0.2 bef...2015

💬Community

2
Bugzilla
CVE-2015-3194 CVE-2015-3195 CVE-2015-3196 mingw-openssl: various flaws [fedora-all]2015-12-10
Bugzilla
CVE-2015-3196 OpenSSL: Race condition handling PSK identify hint2015-12-04
CVE-2015-3196 (MEDIUM CVSS 4.3) | ssl/s3_clnt.c in OpenSSL 1.0.0 befo | cvebase.io