5

CVE-2015-0290

The multi-block feature in the ssl3_write_bytes function in s3_pkt.c in OpenSSL 1.0.2 before 1.0.2a on 64-bit x86 platforms with AES NI support does not properly handle certain non-blocking I/O cases, which allows remote attackers to cause a denial of service (pointer corruption and application crash) via unspecified vectors.

Data is provided by the National Vulnerability Database (NVD)
OpenSSLOpenSSL Version1.0.2
OpenSSLOpenSSL Version1.0.2 Updatebeta1
OpenSSLOpenSSL Version1.0.2 Updatebeta2
OpenSSLOpenSSL Version1.0.2 Updatebeta3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 19.66% 0.953
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
http://marc.info/?l=bugtraq&m=144050155601375&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=143748090628601&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=144050297101809&w=2
Third Party Advisory
Mailing List
http://www.securitytracker.com/id/1031929
Third Party Advisory
VDB Entry
http://www.securityfocus.com/bid/73226
Third Party Advisory
VDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=1202345
Third Party Advisory
Issue Tracking