PT-2014-1693 · Novell+22 · Suse Linux Enterprise Desktop+37

Bodo Möller

+2

·

Published

1999-01-01

·

Updated

2026-05-28

·

CVE-2014-3566

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenSSL versions prior to 1.0.1i OpenSSL through 1.0.1i PAN-OS versions 6.1.1 and earlier PAN-OS versions 6.0.7 and earlier PAN-OS versions 5.1.x and 5.0.x EOS versions 4.12.0 through 4.12.7.1 EOS versions 4.13.0 through 4.13.6 Apple mac os x (affected versions not specified) Debian debian linux (affected versions not specified) Fedoraproject fedora (affected versions not specified) IBM aix (affected versions not specified) IBM vios (affected versions not specified) Mageia (affected versions not specified) Netbsd (affected versions not specified) Novell suse linux enterprise desktop (affected versions not specified) Novell suse linux enterprise server (affected versions not specified) Novell suse linux enterprise software development kit (affected versions not specified) OpenSUSE (affected versions not specified) Oracle database (affected versions not specified) Redhat enterprise linux (affected versions not specified) Redhat enterprise linux desktop (affected versions not specified) Redhat enterprise linux desktop supplementary (affected versions not specified) Redhat enterprise linux server (affected versions not specified) Redhat enterprise linux server supplementary (affected versions not specified) Redhat enterprise linux workstation (affected versions not specified) Redhat enterprise linux workstation supplementary (affected versions not specified) Check Point GAiA (affected versions not specified) HPE iLO (affected versions not specified) Huawei products (affected versions not specified) Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25
Description The SSL protocol 3.0 uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, also known as the "POODLE" issue. This allows an attacker to decrypt some encrypted contents under certain conditions. The conditions of successful exploitation are somewhat similar to the BEAST attack, which requires several conditions to be met for successful exploitation, including a man-in-the-middle position in the network and the ability to direct the victim client to send many repeated requests to the vulnerable server on behalf of the attacker. Due to the conditions required of a successful attack scenario, the risk of exploitation is not particularly high.
Recommendations For OpenSSL versions prior to 1.0.1i, update to a version newer than 1.0.1i to mitigate the risk. For PAN-OS versions 6.1.1 and earlier, update to a version newer than 6.1.1 to mitigate the risk. For PAN-OS versions 6.0.7 and earlier, update to a version newer than 6.0.7 to mitigate the risk. For PAN-OS versions 5.1.x and 5.0.x, update to a version newer than 5.1.x and 5.0.x to mitigate the risk. For EOS versions 4.12.0 through 4.12.7.1, update to a version newer than 4.12.7.1 to mitigate the risk. For EOS versions 4.13.0 through 4.13.6, update to a version newer than 4.13.6 to mitigate the risk. For other affected products, update to a version that includes a fix for the POODLE issue. As a temporary workaround, consider disabling the use of SSLv3 protocol until a patch is available. Restrict access to the vulnerable server to minimize the risk of exploitation. Avoid using the SSLv3 protocol in the affected API endpoints until the issue is resolved.

Exploit

Fix

Weakness Enumeration

Related Identifiers

ALT-PU-2014-2312
ALT-PU-2016-2016
BDU:2015-00642
CESA-2015_0067
CESA-2015_0069
CESA-2015_0085
CVE-2014-3566
DLA-157-1
DLA-282-1
DLA-400-1
DSA-3092-1
DSA-3144-1
DSA-3147-1
DSA-3253-1
DSA-3489-1
HPSBUX03162
HPSBUX03273
HPSBUX03281
LOWSTRENGTHCIPHERSUITESCHECK
MGASA-2014-0416
MGASA-2014-0489
OPENSUSE-SU-2014_1331-1
OPENSUSE-SU-2015_0190-1
OPENSUSE-SU-2016_0640-1
OPENSUSE-SU-2024:10275-1
OPENSUSE-SU-2024:10311-1
OPENSUSE-SU-2024:10428-1
OPENSUSE-SU-2024:10479-1
OPENSUSE-SU-2024:10534-1
OPENSUSE-SU-2024:11388-1
RHSA-2014:1876
RHSA-2014:1877
RHSA-2014:1880
RHSA-2014:1881
RHSA-2014:1882
RHSA-2014_1877
RHSA-2014_1880
RHSA-2014_1881
RHSA-2014_1882
RHSA-2015:0067
RHSA-2015:0068
RHSA-2015:0069
RHSA-2015:0079
RHSA-2015:0080
RHSA-2015:0085
RHSA-2015:0086
RHSA-2015:0264
RHSA-2015:1545
RHSA-2015:1546
RHSA-2015_0067
RHSA-2015_0068
RHSA-2015_0069
RHSA-2015_0079
RHSA-2015_0080
RHSA-2015_0085
RHSA-2015_0086
SUSE-FU-2022:0039-1
SUSE-FU-2022:0445-1
SUSE-RU-2015:0462-1
SUSE-RU-2015:0769-1
SUSE-RU-2015:1175-1
SUSE-SU-2014_1361-1
SUSE-SU-2014_1387-1
SUSE-SU-2014_1447-1
SUSE-SU-2014_1512-1
SUSE-SU-2014_1519-1
SUSE-SU-2014_1558-1
SUSE-SU-2015:0182-2
SUSE-SU-2015:0336-1
SUSE-SU-2015:0343-1
SUSE-SU-2015:0343-2
SUSE-SU-2015:0503-1
SUSE-SU-2015:0543-1
SUSE-SU-2015:0545-1
SUSE-SU-2015:0545-2
SUSE-SU-2015:0546-1
SUSE-SU-2015:0578-1
SUSE-SU-2015:0833-1
SUSE-SU-2015:1086-2
SUSE-SU-2015:1086-4
SUSE-SU-2015:1182-1
SUSE-SU-2015:1182-2
SUSE-SU-2015:1183-1
SUSE-SU-2015:1184-1
SUSE-SU-2015:1184-2
SUSE-SU-2015:1185-1
SUSE-SU-2015_0010-1
SUSE-SU-2015_0336-1
SUSE-SU-2015_0503-1
SUSE-SU-2016:1457-1
SUSE-SU-2016:1459-1
SUSE-SU-2016:2285-1
SUSE-SU-2016:2329-1
SUSE-SU-2016:2396-1
SUSE-SU-2016_1457-1
SUSE-SU-2016_1459-1
SUSE-SU-403
USN-2486-1
USN-2487-1

Affected Products

Aix
Alt Linux
Centos
Check Point Gaia
Cisco Ios Xr
Debian
Eos
Fedora
Gaia
Hpe Ilo
Hp-Ux
Huawei Vrp
Ibm Aix
Java Platform
Java Se
Junos
Mageia
Netbsd
Openssl
Opensuse
Oracle Database
Pan-Os
Red Hat
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Desktop Supplementary
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Server Supplementary
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Workstation Supplementary
Suse Linux Enterprise Desktop
Suse Linux Enterprise Server
Suse Linux Enterprise Software Development Kit
Suse
Ubuntu
Vios
Vmware Vcenter
Ilo
Apple Macos