CVE-2015-3196
Severity
4.3MEDIUM
EPSS
7.4%
top 8.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 6
Latest updateMay 14
Description
ssl/s3_clnt.c in OpenSSL 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1p, and 1.0.2 before 1.0.2d, when used for a multi-threaded client, writes the PSK identity hint to an incorrect data structure, which allows remote servers to cause a denial of service (race condition and double free) via a crafted ServerKeyExchange message.
CVSS vector
AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9
Affected Packages8 packages
Also affects: Debian Linux 7.0, 8.0, Fedora 22, Ubuntu Linux 12.04, 14.04, 15.04, 15.10, Enterprise Linux 7.2, 7.3, 7.4, 6.7, 7.5, 7.6
Patches
🔴Vulnerability Details
3📋Vendor Advisories
5Debian▶
CVE-2015-3196: openssl - ssl/s3_clnt.c in OpenSSL 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1p, and 1.0.2 bef...↗2015