PT-2014-9090 · Openssl+9 · Openssl+9

Published

1970-01-01

·

Updated

2024-06-15

·

CVE-2014-3470

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions OpenSSL versions prior to 0.9.8za OpenSSL versions prior to 1.0.0m OpenSSL versions prior to 1.0.1h libopenssl1 0 0 versions (affected versions not specified) libopenssl1 0 0-debuginfo versions (affected versions not specified) libopenssl1 0 0-debuginfo-x86 versions (affected versions not specified) libopenssl1 0 0-debuginfo-32bit versions (affected versions not specified) libopenssl-devel versions (affected versions not specified) libopenssl-devel-32bit versions (affected versions not specified) libopenssl0 9 8-hmac versions (affected versions not specified) libopenssl0 9 8-hmac-32bit versions (affected versions not specified) openssl-debugsource versions (affected versions not specified) openssl-debuginfo versions (affected versions not specified) openssl-doc versions (affected versions not specified)
Description The issue allows remote attackers to cause a denial of service by triggering a NULL certificate value when an anonymous ECDH cipher suite is used. This can lead to a NULL pointer dereference and client crash. The vulnerability can be exploited remotely, potentially disrupting the confidentiality, integrity, and availability of protected information.
Recommendations For OpenSSL versions prior to 0.9.8za, update to version 0.9.8za or later. For OpenSSL versions prior to 1.0.0m, update to version 1.0.0m or later. For OpenSSL versions prior to 1.0.1h, update to version 1.0.1h or later. For libopenssl1 0 0, libopenssl1 0 0-debuginfo, libopenssl1 0 0-debuginfo-x86, libopenssl1 0 0-debuginfo-32bit, libopenssl-devel, libopenssl-devel-32bit, libopenssl0 9 8-hmac, libopenssl0 9 8-hmac-32bit, openssl-debugsource, openssl-debuginfo, and openssl-doc, update to a version that is not affected by this issue, as the specific affected versions are not specified. As a temporary workaround, consider disabling the use of anonymous ECDH cipher suites in OpenSSL clients until a patch is available.

Exploit

Fix

DoS

NULL Pointer Dereference

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-00124
BDU:2015-04312
BDU:2015-04313
BDU:2015-05844
BDU:2015-05845
BDU:2015-05846
BDU:2015-05847
BDU:2015-05848
BDU:2015-05849
BDU:2015-05850
BDU:2015-05851
BDU:2015-05852
BDU:2015-05853
BDU:2015-05854
BDU:2015-05855
BDU:2015-09698
CESA-2014_0625
CVE-2014-3470
DLA-0003-1
DSA-2950-1
HPSBUX03046
MGASA-2014-0255
OPENSUSE-SU-2014_0764-1
OPENSUSE-SU-2014_0765-1
OPENSUSE-SU-2016_0640-1
OPENSUSE-SU-2024:10271-1
OPENSUSE-SU-2024:10529-1
OPENSUSE-SU-2024:11127-1
RHSA-2014:0625
RHSA-2014:0628
RHSA-2014:0679
RHSA-2014_0625
RHSA-2014_0679
SUSE-FU-2022:0445-1
SUSE-RU-2015:0769-1
SUSE-SU-2015:0182-2
SUSE-SU-2015:0543-1
SUSE-SU-2015:0545-1
SUSE-SU-2015:0545-2
SUSE-SU-2015:0546-1
SUSE-SU-2015:0578-1
SUSE-SU-2015:0743-1
SUSE-SU-2015:1182-1
SUSE-SU-2015:1182-2
SUSE-SU-2015:1183-1
SUSE-SU-2015:1184-1
SUSE-SU-2015:1184-2
SUSE-SU-2015:1185-1
SUSE-SU-403
USN-2232-1
USN-2232-2
USN-2232-3

Affected Products

Centos
Hp-Ux
Huawei Vrp
Ibm Aix
Mariadb Server
Openssl
Red Hat
Suse
Ubuntu
Vmware Vcenter