CVE-2015-3196
mediumCVSS v3 Base Score
4.3
AV:N/AC:M/Au:N/C:N/I:N/A:P
EPSS Score
7.4%
Exploitation probability in 30 days
Top 8% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
M
Confidentiality
None
Integrity
None
Availability
P
Vulnerability Report
Generated by CyberWatcher
Description
ssl/s3_clnt.c in OpenSSL 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1p, and 1.0.2 before 1.0.2d, when used for a multi-threaded client, writes the PSK identity hint to an incorrect data structure, which allows remote servers to cause a denial of service (race condition and double free) via a crafted ServerKeyExchange message.
CWE
CWE-362Affected Products
hp icewall ssohp icewall sso agent optionopenssl openssloracle vm virtualboxfedoraproject fedoraredhat enterprise linux desktopredhat enterprise linux serverredhat enterprise linux server ausredhat enterprise linux server eusredhat enterprise linux server tus