CVE-2010-3864 describes multiple race conditions in OpenSSL versions 0.9.8f through 0.9.8o, 1.0.0, and 1.0.0a, specifically within the ssl/t1_lib.c file. These vulnerabilities, triggered when multi-threading and internal caching are enabled on a TLS server, could lead to a heap-based buffer overflow via client data related to TLS server name extensions or elliptic curve cryptography. With a CVSS score of 7.6, this vulnerability is considered highly severe due to its network-based attack vector, high attack complexity, and potential for complete compromise of confidentiality, integrity, and availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.9.8fCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:0.9.8f:*:*:*:*:*:*:* | ||
0.9.8gCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:0.9.8g:*:*:*:*:*:*:* | ||
0.9.8hCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:0.9.8h:*:*:*:*:*:*:* | ||
0.9.8iCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:0.9.8i:*:*:*:*:*:*:* | ||
0.9.8jCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:0.9.8j:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:H/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.