CVE-2015-1791

Description

Race condition in the ssl3_get_new_session_ticket function in ssl/s3_clnt.c in OpenSSL before 0.9.8zg, 1.0.0 before 1.0.0s, 1.0.1 before 1.0.1n, and 1.0.2 before 1.0.2b, when used for a multi-threaded client, allows remote attackers to cause a denial of service (double free and application crash) or possibly have unspecified other impact by providing a NewSessionTicket during an attempt to reuse a ticket that had been obtained earlier.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
10.249

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2015-1792,CVE-2015-1790,CVE-2015-1789,CVE-2015-1791 are fixed in OpenSSL (x64) 0.9.8zgWindows
Vulnerabilities CVE-2015-1792,CVE-2015-1790,CVE-2015-1789,CVE-2015-1791 are fixed in OpenSSL (x64) 1.0.0sWindows
Vulnerabilities CVE-2015-1792,CVE-2015-1790,CVE-2015-1789,CVE-2015-1788,CVE-2015-1791 are fixed in OpenSSL (x64) 1.0.1nWindows
Vulnerabilities CVE-2015-1792,CVE-2015-1790,CVE-2015-1789,CVE-2015-1788,CVE-2015-1791 are fixed in OpenSSL (x64) 1.0.2bWindows
Vulnerabilities CVE-2015-1791 are affected in Oracle PeopleSoft Enterprise PeopleTools 6.8Windows
Multiple vulnerabilities are affected in Oracle Primavera P6 Enterprise Project Portfolio Management 8.3Windows
Multiple vulnerabilities are affected in Oracle Primavera P6 Enterprise Project Portfolio Management 8.4Windows
Multiple vulnerabilities are affected in Oracle Primavera P6 Enterprise Project Portfolio Management 15.1Windows
Multiple vulnerabilities are fixed in OS X Yosemite 10.10.5 UpdateMac
Multiple vulnerabilities are fixed in OS X Yosemite 10.10.5 Combo UpdateMac
Multiple Vulnerabilities in OpenSSL (June 2015) Affecting Cisco Products For Cisco IOS XE SoftwareNCM
Multiple Vulnerabilities in OpenSSL (June 2015) Affecting Cisco Products For Cisco NX-OS SoftwareNCM
Concurrent Execution using Shared Resource with Improper Synchronization (Race Condition) Vulnerability (CVE-2015-1791)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-1706107Security Update for Cisco IOS XE Software 5.2(1)SV5(1.3a)
PATCH-1706149Security Update for Cisco NX-OS Software 4.1(3a)UCSM
PATCH-600354OS X Yosemite 10.10.5 Update
PATCH-600458OS X Yosemite 10.10.5 Combo Update

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234