Logo
vulnerabilityCVE-2015-3216
Name
CVE-2015-3216
Source
NVD ( link)Debian ( link)
Description
Race condition in a certain Red Hat patch to the PRNG lock implementation in the ssleay_rand_bytes function in OpenSSL, as distributed in openssl-1.0.1e-25.el7 in Red Hat Enterprise Linux (RHEL) 7 and other products, allows remote attackers to cause a denial of service (application crash) by establishing many TLS sessions to a multithreaded server, leading to use of a negative value for a certain length field.
Published Date
Updated Date
Workaround
-
Advisories

Analysis#


Affected Component
Analysis
openssl
False Positive

Vulnerability Rating#


4.3
CVSSv2

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
3.5.7
Not Affected
buildroot
master
3.6.3
Not Affected
openwrt
master
3.5.7-r1
Not Affected
openwrt
openwrt-25.12
3.5.7-r1
Not Affected
yocto
kirkstone
3.0.19
Not Affected
yocto
scarthgap
3.5.7
Not Affected