CVE-2015-3216 describes a race condition in a Red Hat patch to OpenSSL's PRNG lock implementation, specifically affecting openssl-1.0.1e-25.el7 in Red Hat Enterprise Linux 7 and other related products. This vulnerability allows remote attackers to trigger a denial of service, causing an application crash, by initiating numerous TLS sessions to a multithreaded server. The vulnerability has a CVSS score of 4.3, indicating a medium attack complexity and a partial impact on availability, with no impact on confidentiality or integrity. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:* | ||
1.0.1e-25.el7CPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.1e-25.el7:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:N/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.