CVE-2011-3210

EPSS 5.9%
發布日:2011/9/22修改日:2026/4/28

描述

The ephemeral ECDH ciphersuite functionality in OpenSSL 0.9.8 through 0.9.8r and 1.0.x before 1.0.0e does not ensure thread safety during processing of handshake messages from clients, which allows remote attackers to cause a denial of service (daemon crash) via out-of-order messages that violate the TLS protocol.

受影響套件(1)

參考連結(1)