Race condition in the ssl3_read_bytes function in s3_pkt.c in OpenSSL through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, allows remote attackers to inject data across sessions or cause a denial of service (use-after-free and parsing error) via an SSL connection in a multithreaded environment.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
History
No history.
Information
Published : 2014-04-14 22:38
Updated : 2022-08-29 20:53
NVD link : CVE-2010-5298
Mitre link : CVE-2010-5298
CVE.ORG link : CVE-2010-5298
JSON object : View
Products Affected
suse
- linux_enterprise_desktop
- linux_enterprise_software_development_kit
- linux_enterprise_server
- linux_enterprise_workstation_extension
mariadb
- mariadb
fedoraproject
- fedora
openssl
- openssl
CWE
CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')