PT-2014-1884 · Openssl+5 · Openssl+5

Published

2014-01-06

·

Updated

2024-06-15

·

CVE-2013-4353

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions OpenSSL versions prior to 1.0.1f Gentoo Linux (affected versions not specified)
Description The issue allows remote TLS servers to cause a denial of service, resulting in a NULL pointer dereference and application crash, via a crafted Next Protocol Negotiation record in a TLS handshake. Exploitation of this issue can lead to disruption of protected information and can be carried out remotely.
Recommendations For OpenSSL versions prior to 1.0.1f, update to version 1.0.1f or later to resolve the issue. For Gentoo Linux, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1019
BDU:2015-09745
CESA-2014_0015
CVE-2013-4353
DSA-2837-1
MGASA-2014-0012
OPENSUSE-SU-2024:10271-1
OPENSUSE-SU-2024:10529-1
OPENSUSE-SU-2024:11127-1
RHSA-2014:0015
RHSA-2014:0041
RHSA-2014:0416
RHSA-2014_0015
SUSE-FU-2022:0445-1

Affected Products

Alt Linux
Centos
Gentoo Linux
Ibm Aix
Openssl
Red Hat