CVE-2010-3864
openssl - buffer overflow
EPSS 22.1%
描述
Multiple race conditions in ssl/t1_lib.c in OpenSSL 0.9.8f through 0.9.8o, 1.0.0, and 1.0.0a, when multi-threading and internal caching are enabled on a TLS server, might allow remote attackers to execute arbitrary code via client data that triggers a heap-based buffer overflow, related to (1) the TLS server name extension and (2) elliptic curve cryptography.
如何修補 CVE-2010-3864
要修補 CVE-2010-3864,請將受影響套件升級到下列已修補版本。
- Debian/openssl—升級至 0.9.8o-3 或更新版本
- Debian/openssl—升級至 0.9.8g-15+lenny9 或更新版本
CVE-2010-3864 正在被利用嗎?
中等 — EPSS 為 22.1%,可持續追蹤但非最高優先。
受影響套件(2)
- from 0, < 0.9.8o-3
- from 0, < 0.9.8g-15+lenny9