PT-2013-1150 · Openssl+8 · Openssl+11

Published

2013-12-01

·

Updated

2024-06-15

·

CVE-2014-3571

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions OpenSSL versions 0.9.8 through 0.9.8zd OpenSSL versions 1.0.0 through 1.0.0p OpenSSL versions 1.0.1 through 1.0.1k
Description The issue allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted DTLS message that is processed with a different read operation for the handshake header than for the handshake body, related to the dtls1 get record function in d1 pkt.c and the ssl3 read n function in s3 pkt.c. This can lead to disruption of protected information availability. The exploitation can be carried out remotely.
Recommendations For versions 0.9.8 through 0.9.8zd, update to version 0.9.8zd or later. For versions 1.0.0 through 1.0.0p, update to version 1.0.0p or later. For versions 1.0.1 through 1.0.1k, update to version 1.0.1k or later. As a temporary workaround, consider restricting access to DTLS messages to minimize the risk of exploitation.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-1023
ALT-PU-2015-2113
BDU:2015-06127
BDU:2015-06128
BDU:2015-06129
BDU:2015-06130
BDU:2015-06131
BDU:2015-09142
BDU:2015-09143
BDU:2015-09144
BDU:2015-09145
BDU:2015-09146
BDU:2015-09819
BDU:2015-09905
CESA-2015_0066
CVE-2014-3571
DLA-132-1
DSA-3125-1
HPSBUX03162
HPSBUX03244
MGASA-2015-0022
OPENSUSE-SU-2015_0130-1
OPENSUSE-SU-2016_0640-1
OPENSUSE-SU-2024:10271-1
OPENSUSE-SU-2024:10529-1
OPENSUSE-SU-2024:11127-1
RHSA-2015:0066
RHSA-2015_0066
SUSE-FU-2022:0445-1
SUSE-RU-2015:0769-1
SUSE-SU-2015:0305-1
SUSE-SU-2015:0545-1
SUSE-SU-2015:0545-2
SUSE-SU-2015:0546-1
SUSE-SU-2015:0620-1
SUSE-SU-2015:0946-1
SUSE-SU-2015:1177-1
SUSE-SU-2015:1182-1
SUSE-SU-2015:1182-2
SUSE-SU-2015:1184-1
SUSE-SU-2015:1184-2
SUSE-SU-2015:1185-1
SUSE-SU-403
USN-2459-1

Affected Products

Alt Linux
Centos
Cisco Ios
Cisco Ios Xe
Cisco Nexus
Cisco Wls
Hp-Ux
Ibm Aix
Openssl
Red Hat
Suse
Ubuntu