CVE-2015-3196

medium HPE
CVSS v3 Base Score
4.3
AV:N/AC:M/Au:N/C:N/I:N/A:P
EPSS Score
7.4%
Exploitation probability in 30 days
Top 8% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
M
Confidentiality
None
Integrity
None
Availability
P
Published: December 6, 2015 (3812 days ago)
Last Modified: May 6, 2026
Vendor: HPE
Source: NVD

Description

ssl/s3_clnt.c in OpenSSL 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1p, and 1.0.2 before 1.0.2d, when used for a multi-threaded client, writes the PSK identity hint to an incorrect data structure, which allows remote servers to cause a denial of service (race condition and double free) via a crafted ServerKeyExchange message.

CWE

CWE-362

Affected Products

hp icewall ssohp icewall sso agent optionopenssl openssloracle vm virtualboxfedoraproject fedoraredhat enterprise linux desktopredhat enterprise linux serverredhat enterprise linux server ausredhat enterprise linux server eusredhat enterprise linux server tus

References