CVE-2015-3216
published 2015-07-07CVE-2015-3216: Race condition in a certain Red Hat patch to the PRNG lock implementation in the ssleay_rand_bytes function in OpenSSL, as distributed in openssl-1.0.1e-25.el7…
PriorityP422medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
4.30%
90.0th percentile
Race condition in a certain Red Hat patch to the PRNG lock implementation in the ssleay_rand_bytes function in OpenSSL, as distributed in openssl-1.0.1e-25.el7 in Red Hat Enterprise Linux (RHEL) 7 and other products, allows remote attackers to cause a denial of service (application crash) by establishing many TLS sessions to a multithreaded server, leading to use of a negative value for a certain length field.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openssl | — | — |
| openssl | openssl | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
vendor_debian4.3LOW
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
openssl: Crash in ssleay_rand_bytes due to locking regression
vendor_redhat·2015-05-28·CVSS 4.3
CVE-2015-3216 [MEDIUM] openssl: Crash in ssleay_rand_bytes due to locking regression
openssl: Crash in ssleay_rand_bytes due to locking regression
Race condition in a certain Red Hat patch to the PRNG lock implementation in the ssleay_rand_bytes function in OpenSSL, as distributed in openssl-1.0.1e-25.el7 in Red Hat Enterprise Linux (RHEL) 7 and other products, allows remote attackers to cause a denial of service (application crash) by establishing many TLS sessions to a multithreaded server, leading to use of a negative value for a certain length field.
A regression was found in the ssleay_rand_bytes() function in the versions of OpenSSL shipped with Red Hat Enterprise Linux 6 and 7. This regression could cause a multi-threaded application to crash.
Statement: This issue does not affect the version of OpenSSL package as shipped with Red Hat Enterprise Linux 5.
Package
Debian
CVE-2015-3216: openssl - Race condition in a certain Red Hat patch to the PRNG lock implementation in the...
vendor_debian·2015·CVSS 4.3
CVE-2015-3216 [MEDIUM] CVE-2015-3216: openssl - Race condition in a certain Red Hat patch to the PRNG lock implementation in the...
Race condition in a certain Red Hat patch to the PRNG lock implementation in the ssleay_rand_bytes function in OpenSSL, as distributed in openssl-1.0.1e-25.el7 in Red Hat Enterprise Linux (RHEL) 7 and other products, allows remote attackers to cause a denial of service (application crash) by establishing many TLS sessions to a multithreaded server, leading to use of a negative value for a certain length field.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-3522-gq68-vxp6: Race condition in a certain Red Hat patch to the PRNG lock implementation in the ssleay_rand_bytes function in OpenSSL, as distributed in openssl-1
ghsa_unreviewed·2022-05-14
CVE-2015-3216 [MEDIUM] GHSA-3522-gq68-vxp6: Race condition in a certain Red Hat patch to the PRNG lock implementation in the ssleay_rand_bytes function in OpenSSL, as distributed in openssl-1
Race condition in a certain Red Hat patch to the PRNG lock implementation in the ssleay_rand_bytes function in OpenSSL, as distributed in openssl-1.0.1e-25.el7 in Red Hat Enterprise Linux (RHEL) 7 and other products, allows remote attackers to cause a denial of service (application crash) by establishing many TLS sessions to a multithreaded server, leading to use of a negative value for a certain length field.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-3216 CVE-2015-1789 CVE-2015-1790 CVE-2015-1792 CVE-2015-1791 CVE-2014-8176: OpenSSL multiple security issues [fedora-all]
bugzilla·2015-06-12·CVSS 7.5
CVE-2015-3216 [HIGH] CVE-2015-3216 CVE-2015-1789 CVE-2015-1790 CVE-2015-1792 CVE-2015-1791 CVE-2014-8176: OpenSSL multiple security issues [fedora-all]
CVE-2015-3216 CVE-2015-1789 CVE-2015-1790 CVE-2015-1792 CVE-2015-1791 CVE-2014-8176: OpenSSL multiple security issues [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOT
Bugzilla
CVE-2015-3216 openssl: Crash in ssleay_rand_bytes due to locking regression
bugzilla·2015-06-03·CVSS 4.3
CVE-2015-3216 [MEDIUM] CVE-2015-3216 openssl: Crash in ssleay_rand_bytes due to locking regression
CVE-2015-3216 openssl: Crash in ssleay_rand_bytes due to locking regression
A regression was found in the openssl packages shipped with Red Hat Enterprise Linux 6 and 7, leading to a denial-of-service when openssl is used with multi-threaded applications.
More details about this issue is available at:
https://bugzilla.redhat.com/show_bug.cgi?id=1226204
Discussion:
(In reply to Huzaifa S. Sidhpurwala from comment #0)
> More details about this issue is available at:
>
> https://bugzilla.redhat.com/show_bug.cgi?id=1226204
Note: Since the above bug is closed, more information about this flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=1225994
---
Created openssl tracking bugs for this issue:
Affects: fedora-all [bug 1231051]
---
*** Bug 1227734 h
http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00023.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00024.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00006.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1115.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2957.htmlhttp://www.securityfocus.com/bid/75219http://www.securitytracker.com/id/1032587https://bugzilla.redhat.com/show_bug.cgi?id=1225994http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00023.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00024.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00006.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1115.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2957.htmlhttp://www.securityfocus.com/bid/75219http://www.securitytracker.com/id/1032587https://bugzilla.redhat.com/show_bug.cgi?id=1225994
2015-07-07
Published