Resource management error in OpenSSL - CVE-2011-3210

 

Resource management error in OpenSSL - CVE-2011-3210

Published: September 22, 2011 / Updated: July 28, 2020


Vulnerability identifier: #VU32856
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2011-3210
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform service disruption.

The ephemeral ECDH ciphersuite functionality in OpenSSL 0.9.8 through 0.9.8r and 1.0.x before 1.0.0e does not ensure thread safety during processing of handshake messages from clients, which allows remote attackers to cause a denial of service (daemon crash) via out-of-order messages that violate the TLS protocol.


Affected software

OpenSSL
openssl (Alpine package)

How to mitigate CVE-2011-3210

Install update from vendor's website.

OpenSSL - update to 0.9.8s
openssl (Alpine package) - update to 1.0.0e-r0

External References

Related Security Bulletins