PT-2011-1149 · Openssl+2 · Openssl+2

Neel Mehta

·

Published

2011-02-08

·

Updated

2024-06-15

·

CVE-2011-0014

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions OpenSSL versions 0.9.8h through 0.9.8q OpenSSL versions 1.0.0 through 1.0.0c OpenSSL versions prior to 1.0.0e
Description The issue allows remote attackers to cause a denial of service (crash) and possibly obtain sensitive information in applications that use OpenSSL, via a malformed ClientHello handshake message that triggers an out-of-bounds memory access. Exploitation of the vulnerabilities may lead to a violation of confidentiality, integrity, and availability of protected information and can be carried out remotely.
Recommendations For OpenSSL versions 0.9.8h through 0.9.8q, update to a version later than 0.9.8q. For OpenSSL versions 1.0.0 through 1.0.0c, update to a version later than 1.0.0c. For OpenSSL versions prior to 1.0.0e, update to version 1.0.0e or later.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-09418
CVE-2011-0014
DSA-2162-1
HPSBUX02689
OPENSUSE-SU-2024:10271-1
OPENSUSE-SU-2024:10529-1
OPENSUSE-SU-2024:11127-1
RHSA-2011:0677
RHSA-2011_0677
SUSE-FU-2022:0445-1
SUSE-SU-2015:1184-1
SUSE-SU-403

Affected Products

Hp-Ux
Openssl
Red Hat