The multi-block feature in the ssl3_write_bytes function in s3_pkt.c in OpenSSL 1.0.2 before 1.0.2a on 64-bit x86 platforms with AES NI support does not properly handle certain non-blocking I/O cases, which allows remote attackers to cause a denial of service (pointer corruption and application crash) via unspecified vectors.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Cisco Apic | — | Upgrade to the latest version of Cisco APIC to resolve this vulnerability. | May 11, 2026 | Mar 20, 2015 |
| Cisco Xe | — | Upgrade to the latest version of Cisco IOS XE | Jul 30, 2019 | Mar 19, 2015 |
| Cisco Xr Os | — | Upgrade to the latest version of Cisco IOS-XR to resolve this vulnerability. | May 19, 2021 | Mar 20, 2015 |
| Gentoo Linux | — | Upgrade dev-libs/openssl. | Oct 30, 2017 | Mar 19, 2015 |
| Hpsim | — | Upgrade to the latest version of HP Systems Insight Manager | Oct 13, 2015 | Mar 19, 2015 |
| Hpsmh | — | Upgrade to the latest version of HP System Management Homepage | Oct 13, 2015 | Mar 19, 2015 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | Mar 20, 2015 | Mar 19, 2015 |
| Oracle Solaris | — | Upgrade library/security/openssl/openssl-fips-140 to version 2.0.6-0.175.2.9.0.4.0 on Solaris 11.2Upgrade library/security/openssl to version 1.0.1.13-0.175.2.9.0.4.0 on Solaris 11.2 | May 29, 2017 | Mar 19, 2015 |
| Pulse Secure Pulse Connect Secure | — | Update Pulse Connect Secure to version 8.0R11Update Pulse Connect Secure to version 7.4R13.4Update Pulse Connect Secure to version 8.1R3.1Update Pulse Connect Secure to version 7.1R22.1 | Oct 28, 2020 | Mar 19, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub