5
CVSSv2

CVE-2010-0740

Published: 26/03/2010 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The ssl3_get_record function in ssl/s3_pkt.c in OpenSSL 0.9.8f up to and including 0.9.8m allows remote malicious users to cause a denial of service (crash) via a malformed record in a TLS connection that triggers a NULL pointer dereference, related to the minor version number. NOTE: some of these details are obtained from third party information.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openssl openssl 0.9.8m

openssl openssl 0.9.8g

openssl openssl 0.9.8k

openssl openssl 0.9.8j

openssl openssl 0.9.8l

openssl openssl 0.9.8i

openssl openssl 0.9.8f

openssl openssl 0.9.8h

Vendor Advisories

Debian Bug report logs - #575607 CVE-2010-0740: openssl denial-of-service Package: openssl; Maintainer for openssl is Debian OpenSSL Team <pkg-openssl-devel@listsaliothdebianorg>; Source for openssl is src:openssl (PTS, buildd, popcon) Reported by: Michael Gilbert <michaelsgilbert@gmailcom> Date: Sat, 27 Mar 20 ...

Exploits

/*********************************************************** * hoagie_openssl_record_of_deathc * OPENSSL REMOTE DENIAL-OF-SERVICE EXPLOIT * - OpenSSL 098m (short = 16 bit) * - OpenSSL 098f through 098m (short != 16 bit) * * CVE-2010-0740 * * Bug discovered by: * Bodo Moeller and Adam Langley (Google) * Philip Olausson <po@secwe ...
OpenSSL versions 098f through 098m remote denial of service exploit ...