LWN.net Logo

openssl: remote code execution

Package(s):openssl CVE #(s):CVE-2010-3864
Created:November 17, 2010 Updated:November 30, 2010
Description: The OpenSSL project has issued an advisory of a race condition which exists in versions prior to 0.9.8p or 1.0.0b. Successfully exploiting this race can enable a remote attacker to inject code into a server using OpenSSL. It's worth noting, though, that only servers which are (1) multi-threaded, and (2) using OpenSSL's internal caching are vulnerable. So, in particular, Apache servers are not at risk. See this advisory for more information.
Alerts:
Gentoo 201110-01 2011-10-09
SUSE SUSE-SR:2010:022 2010-11-30
Ubuntu USN-1018-1 2010-11-18
Debian DSA-2125-1 2010-11-22
Slackware SSA:2010-326-01 2010-11-22
openSUSE openSUSE-SU-2010:0965-2 2010-11-22
Fedora FEDORA-2010-17847 2010-11-17
Fedora FEDORA-2010-17827 2010-11-17
openSUSE openSUSE-SU-2010:0965-1 2010-11-19
Mandriva MDVSA-2010:238 2010-11-17
Red Hat RHSA-2010:0888-01 2010-11-16

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds