CVE-2011-3210
Publication date 22 September 2011
Last updated 24 July 2024
Ubuntu priority
The ephemeral ECDH ciphersuite functionality in OpenSSL 0.9.8 through 0.9.8r and 1.0.x before 1.0.0e does not ensure thread safety during processing of handshake messages from clients, which allows remote attackers to cause a denial of service (daemon crash) via out-of-order messages that violate the TLS protocol.
Status
Package | Ubuntu Release | Status |
---|---|---|
openssl | ||
Notes
jdstrand
from upstream: applications are only affected by the CRL checking vulnerability if they enable OpenSSL's internal CRL checking which is off by default. For example by setting the verification flag X509_V_FLAG_CRL_CHECK or X509_V_FLAG_CRL_CHECK_ALL The following packages in main use this X509_V_FLAG_CRL_CHECK* curl, dovecot, exim4, freeradius, ipsec-tools, krb5, libio-socket-ssl-perl, libnet-ssleay-perl, likewise-open, mysql-5.1, nmap, openldap, openvpn, postgresql-9.1, ruby1.8, squid, telepathy-gabble, telepathy-salut, wpasupplicant the above need to also support ECDH to be affected
Patch details
Package | Patch details |
---|---|
openssl |
|
References
Related Ubuntu Security Notices (USN)
- USN-1357-1
- OpenSSL vulnerabilities
- 9 February 2012