Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2010-2939 | First vendor Publication | 2010-08-17 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:N/I:N/A:P) | |||
---|---|---|---|
Cvss Base Score | 4.3 | Attack Range | Network |
Cvss Impact Score | 2.9 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Double free vulnerability in the ssl3_get_key_exchange function in the OpenSSL client (ssl/s3_clnt.c) in OpenSSL 1.0.0a, 0.9.8, 0.9.7, and possibly other versions, when using ECDH, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted private key with an invalid prime. NOTE: some sources refer to this as a use-after-free issue. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2939 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-399 | Resource Management Errors |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:12299 | |||
Oval ID: | oval:org.mitre.oval:def:12299 | ||
Title: | DSA-2100-1 openssl -- double free | ||
Description: | George Guninski discovered a double free in the ECDH code of the OpenSSL crypto library, which may lead to denial of service and potentially the execution of arbitrary code. For the stable distribution, this problem has been fixed in version 0.9.8g-15+lenny8. For the unstable distribution, this problem has been fixed in version 0.9.8o-2. We recommend that you upgrade your openssl packages. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-2100-1 CVE-2010-2939 | Version: | 5 |
Platform(s): | Debian GNU/Linux 5.0 | Product(s): | openssl |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:12844 | |||
Oval ID: | oval:org.mitre.oval:def:12844 | ||
Title: | USN-1003-1 -- openssl vulnerabilities | ||
Description: | It was discovered that OpenSSL incorrectly handled return codes from the bn_wexpand function calls. A remote attacker could trigger this flaw in services that used SSL to cause a denial of service or possibly execute arbitrary code with application privileges. This issue only affected Ubuntu 6.06 LTS, 8.04 LTS, 9.04 and 9.10. It was discovered that OpenSSL incorrectly handled certain private keys with an invalid prime. A remote attacker could trigger this flaw in services that used SSL to cause a denial of service or possibly execute arbitrary code with application privileges. The default compiler options for affected releases should reduce the vulnerability to a denial of service | ||
Family: | unix | Class: | patch |
Reference(s): | USN-1003-1 CVE-2009-3245 CVE-2010-2939 | Version: | 5 |
Platform(s): | Ubuntu 9.04 Ubuntu 9.10 Ubuntu 6.06 Ubuntu 8.04 Ubuntu 10.10 Ubuntu 10.04 | Product(s): | openssl |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:20537 | |||
Oval ID: | oval:org.mitre.oval:def:20537 | ||
Title: | Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX | ||
Description: | Double free vulnerability in the ssl3_get_key_exchange function in the OpenSSL client (ssl/s3_clnt.c) in OpenSSL 1.0.0a, 0.9.8, 0.9.7, and possibly other versions, when using ECDH, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted private key with an invalid prime. NOTE: some sources refer to this as a use-after-free issue. | ||
Family: | unix | Class: | vulnerability |
Reference(s): | CVE-2010-2939 | Version: | 4 |
Platform(s): | VMWare ESX Server 4.1 VMWare ESX Server 4.0 | Product(s): | |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:24436 | |||
Oval ID: | oval:org.mitre.oval:def:24436 | ||
Title: | Vulnerability in OpenSSL 1.0.0a, 0.9.8, 0.9.7, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code | ||
Description: | Double free vulnerability in the ssl3_get_key_exchange function in the OpenSSL client (ssl/s3_clnt.c) in OpenSSL 1.0.0a, 0.9.8, 0.9.7, and possibly other versions, when using ECDH, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted private key with an invalid prime. NOTE: some sources refer to this as a use-after-free issue. | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2010-2939 | Version: | 4 |
Platform(s): | Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista Microsoft Windows 7 Microsoft Windows Server 2008 Microsoft Windows Server 2008 R2 Microsoft Windows 8 Microsoft Windows 8.1 Microsoft Windows Server 2012 Microsoft Windows Server 2012 R2 | Product(s): | OpenSSL |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 3 |
OpenVAS Exploits
Date | Description |
---|---|
2012-03-16 | Name : VMSA-2011-0003.2 Third party component updates for VMware vCenter Server, vCe... File : nvt/gb_VMSA-2011-0003.nasl |
2012-02-12 | Name : Gentoo Security Advisory GLSA 201110-01 (openssl) File : nvt/glsa_201110_01.nasl |
2011-05-02 | Name : HP System Management Homepage Multiple Vulnerabilities File : nvt/secpod_hp_smh_mult_vuln_apr11.nasl |
2011-01-24 | Name : FreeBSD Security Advisory (FreeBSD-SA-10:10.openssl.asc) File : nvt/freebsdsa_openssl8.nasl |
2010-10-19 | Name : Ubuntu Update for openssl vulnerabilities USN-1003-1 File : nvt/gb_ubuntu_USN_1003_1.nasl |
2010-10-10 | Name : Debian Security Advisory DSA 2100-1 (openssl) File : nvt/deb_2100_1.nasl |
2010-09-27 | Name : Mandriva Update for openssl MDVSA-2010:168 (openssl) File : nvt/gb_mandriva_MDVSA_2010_168.nasl |
2010-08-10 | Name : OpenSSL 'ssl3_get_key_exchange()' Use-After-Free Memory Corruption Vulnerability File : nvt/gb_openssl_42306.nasl |
0000-00-00 | Name : Slackware Advisory SSA:2010-326-01 openssl File : nvt/esoft_slk_ssa_2010_326_01.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
66946 | OpenSSL ssl/s3_clnt.c ssl3_get_key_exchange() Function Use-After-Free DoS |
Information Assurance Vulnerability Management (IAVM)
Date | Description |
---|---|
2011-05-12 | IAVM : 2011-A-0066 - Multiple Vulnerabilities in VMware Products Severity : Category I - VMSKEY : V0027158 |
Snort® IPS/IDS
Date | Description |
---|---|
2014-01-10 | OpenSSL ssl3_get_key_exchange use-after-free attempt RuleID : 19092 - Revision : 10 - Type : SERVER-OTHER |
2014-01-10 | OpenSSL ssl3_get_key_exchange use-after-free attempt RuleID : 19091 - Revision : 10 - Type : SERVER-OTHER |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2016-03-04 | Name : The remote VMware ESX / ESXi host is missing a security-related patch. File : vmware_VMSA-2011-0003_remote.nasl - Type : ACT_GATHER_INFO |
2014-06-13 | Name : The remote openSUSE host is missing a security update. File : suse_11_3_libopenssl-devel-100927.nasl - Type : ACT_GATHER_INFO |
2012-01-04 | Name : The remote SSL layer is affected by a denial of service vulnerability. File : openssl_0_9_8p_1_0_0e.nasl - Type : ACT_GATHER_INFO |
2011-10-10 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-201110-01.nasl - Type : ACT_GATHER_INFO |
2011-05-05 | Name : The remote openSUSE host is missing a security update. File : suse_11_1_libopenssl-devel-100927.nasl - Type : ACT_GATHER_INFO |
2011-05-05 | Name : The remote openSUSE host is missing a security update. File : suse_11_2_libopenssl-devel-100927.nasl - Type : ACT_GATHER_INFO |
2011-04-22 | Name : The remote web server is affected by multiple vulnerabilities. File : hpsmh_6_3_0_22.nasl - Type : ACT_GATHER_INFO |
2011-02-14 | Name : The remote VMware ESXi / ESX host is missing one or more security-related pat... File : vmware_VMSA-2011-0003.nasl - Type : ACT_GATHER_INFO |
2010-12-02 | Name : The remote SuSE 11 host is missing one or more security updates. File : suse_11_libopenssl-devel-100927.nasl - Type : ACT_GATHER_INFO |
2010-11-22 | Name : The remote Slackware host is missing a security update. File : Slackware_SSA_2010-326-01.nasl - Type : ACT_GATHER_INFO |
2010-11-16 | Name : The remote SuSE 10 host is missing a security-related patch. File : suse_openssl-7174.nasl - Type : ACT_GATHER_INFO |
2010-10-08 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-1003-1.nasl - Type : ACT_GATHER_INFO |
2010-09-02 | Name : The remote Mandriva Linux host is missing one or more security updates. File : mandriva_MDVSA-2010-168.nasl - Type : ACT_GATHER_INFO |
2010-09-01 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-2100.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:07:49 |
|
2024-11-28 12:22:34 |
|
2024-08-02 12:14:10 |
|
2024-08-02 01:03:50 |
|
2024-02-02 01:13:45 |
|
2024-02-01 12:03:45 |
|
2023-11-07 21:47:34 |
|
2023-09-05 12:12:48 |
|
2023-09-05 01:03:37 |
|
2023-09-02 12:12:51 |
|
2023-09-02 01:03:39 |
|
2023-08-12 12:15:18 |
|
2023-08-12 01:03:39 |
|
2023-08-11 12:12:54 |
|
2023-08-11 01:03:47 |
|
2023-08-06 12:12:25 |
|
2023-08-06 01:03:41 |
|
2023-08-04 12:12:31 |
|
2023-08-04 01:03:42 |
|
2023-07-14 12:12:27 |
|
2023-07-14 01:03:40 |
|
2023-03-29 01:14:15 |
|
2023-03-28 12:03:46 |
|
2023-02-13 09:29:09 |
|
2022-10-11 12:11:06 |
|
2022-10-11 01:03:27 |
|
2021-05-04 12:11:50 |
|
2021-04-22 01:12:29 |
|
2020-05-23 00:26:14 |
|
2018-10-11 00:19:54 |
|
2016-04-26 20:00:16 |
|
2016-03-05 13:26:42 |
|
2014-06-14 13:29:03 |
|
2014-02-17 10:56:47 |
|
2014-01-19 21:27:03 |
|
2013-11-11 12:38:52 |
|
2013-05-10 23:30:01 |
|