Unrated severityNVD Advisory· Published Mar 26, 2010· Updated Apr 29, 2026
CVE-2010-0740
CVE-2010-0740
Description
The ssl3_get_record function in ssl/s3_pkt.c in OpenSSL 0.9.8f through 0.9.8m allows remote attackers to cause a denial of service (crash) via a malformed record in a TLS connection that triggers a NULL pointer dereference, related to the minor version number. NOTE: some of these details are obtained from third party information.
Affected products
8cpe:2.3:a:openssl:openssl:0.9.8f:*:*:*:*:*:*:*+ 7 more
- cpe:2.3:a:openssl:openssl:0.9.8f:*:*:*:*:*:*:*
- cpe:2.3:a:openssl:openssl:0.9.8g:*:*:*:*:*:*:*
- cpe:2.3:a:openssl:openssl:0.9.8h:*:*:*:*:*:*:*
- cpe:2.3:a:openssl:openssl:0.9.8i:*:*:*:*:*:*:*
- cpe:2.3:a:openssl:openssl:0.9.8j:*:*:*:*:*:*:*
- cpe:2.3:a:openssl:openssl:0.9.8k:*:*:*:*:*:*:*
- cpe:2.3:a:openssl:openssl:0.9.8l:*:*:*:*:*:*:*
- cpe:2.3:a:openssl:openssl:0.9.8m:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
24- www.openssl.org/news/secadv_20100324.txtnvdPatchVendor Advisory
- www.vupen.com/english/advisories/2010/0710nvdPatchVendor Advisory
- aix.software.ibm.com/aix/efixes/security/openssl_advisory.ascnvd
- lists.apple.com/archives/security-announce/2011//Jun/msg00000.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2010-April/038587.htmlnvd
- marc.infonvd
- marc.infonvd
- secunia.com/advisories/39932nvd
- secunia.com/advisories/42724nvd
- secunia.com/advisories/42733nvd
- secunia.com/advisories/43311nvd
- support.apple.com/kb/HT4723nvd
- www.mandriva.com/security/advisoriesnvd
- www.securityfocus.com/archive/1/516397/100/0/threadednvd
- www.securitytracker.com/idnvd
- www.vmware.com/security/advisories/VMSA-2011-0003.htmlnvd
- www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.htmlnvd
- www.vupen.com/english/advisories/2010/0839nvd
- www.vupen.com/english/advisories/2010/0933nvd
- www.vupen.com/english/advisories/2010/1216nvd
- kb.bluecoat.com/indexnvd
- lists.balabit.com/pipermail/syslog-ng-announce/2011-January/000101.htmlnvd
- lists.balabit.com/pipermail/syslog-ng-announce/2011-January/000102.htmlnvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11731nvd
News mentions
0No linked articles in our index yet.