CVE-2010-5298

Description

Race condition in the ssl3_read_bytes function in s3_pkt.c in OpenSSL through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, allows remote attackers to inject data across sessions or cause a denial of service (use-after-free and parsing error) via an SSL connection in a multithreaded environment.

Risk Information

Base Score
10.0
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS Score
Exploitation Probability
10.73

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities fixed in OpenSSL (x64) 1.0.0mWindows
Multiple vulnerabilities fixed in OpenSSL (x64) 1.0.1hWindows
Secure Socket Layer (SSL) cryptographic library and tools (USN-2192-1) libssl1.0.0_1.0.1f-1ubuntu2.16_i386.debLinux
Secure Socket Layer (SSL) cryptographic library and tools (USN-2192-1) libssl1.0.0_1.0.1f-1ubuntu2.16_amd64.debLinux
Secure Socket Layer (SSL) cryptographic library and tools (USN-2913-3) libssl1.0.0_1.0.1f-1ubuntu2.17_i386.debLinux
Secure Socket Layer (SSL) cryptographic library and tools (USN-2913-3) libssl1.0.0_1.0.1f-1ubuntu2.17_amd64.debLinux
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products For Cisco IOSNCM
Concurrent Execution using Shared Resource with Improper Synchronization (Race Condition) Vulnerability (CVE-2010-5298)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-1706090Security Update for Cisco IOS Amsterdam-17.2.1r

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234