VDB

DEBIAN-CVE-2011-3210

DEBIAN-CVE-2011-3210 PUBLISHED CVSS 8.699999809265137 HIGH

The ephemeral ECDH ciphersuite functionality in OpenSSL 0.9.8 through 0.9.8r and 1.0.x before 1.0.0e does not ensure thread safety during processing of handshake messages from clients, which allows remote attackers to cause a denial of service (daemon crash) via out-of-order messages that violate the TLS protocol.

Risk Scores

CVSS v4.0
8.699999809265137
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
Debian:11openssl0, 0, 0
Debian:14openssl0, 0, 0
Debian:13openssl0, 0, 0
Debian:12openssl0, 0, 0

Timeline

  • Sep 22, 2011 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›