openssl: denial of service
Package(s): | openssl | CVE #(s): | CVE-2015-3216 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Created: | June 16, 2015 | Updated: | June 17, 2015 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Description: | From the Red Hat advisory:
A flaw was found in the way the OpenSSL packages shipped with Red Hat Enterprise Linux 6 and 7 performed locking in the ssleay_rand_bytes() function. This issue could possibly cause a multi-threaded application using OpenSSL to perform an out-of-bounds read and crash. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Alerts: |
|