CVE-2010-5298

Advisory lineage Upstream: 0 Downstream: 10
Modified
Published: 14 Apr 2014, 16:00
Last modified:07 Aug 2024, 04:17

Vulnerability Summary

Overall Risk (default)
low
20/100
CVSS Score
4 MEDIUM
v2.0 (nvd)
EPSS Score
19.07% MEDIUM
19% probability +8.34%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

14 Apr 2014, 16:00
Published
Vulnerability first disclosed
07 Aug 2024, 04:17
Last Modified
Vulnerability information updated

Description

Race condition in the ssl3_read_bytes function in s3_pkt.c in OpenSSL through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, allows remote attackers to inject data across sessions or cause a denial of service (use-after-free and parsing error) via an SSL connection in a multithreaded environment.

CVSS Metrics

  • v2.0MEDIUMScore: 4AV:N/AC:H/Au:N/C:N/I:P/A:P

EPSS Trends

Current EPSS score: 19.07% Percentile: 95%

Techniques & Countermeasures

  • CWE-362Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

    The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

Affected Systems

  • fedoraprojectfedora

    19 | 20

  • mariadbmariadb

    ≥ 10.0.0, < 10.0.13

  • UnknownOpenSSL

    ≤ 1.0.1g

  • suselinux_enterprise_desktop

    12

  • suselinux_enterprise_server

    12

  • suselinux_enterprise_software_development_kit

    12

  • suselinux_enterprise_workstation_extension

    12

References (82)