PT-2014-9092 · Openssl+9 · Openssl+9

Published

1970-01-01

·

Updated

2025-09-29

·

CVE-2014-0195

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions OpenSSL versions prior to 0.9.8za OpenSSL versions prior to 1.0.0m OpenSSL versions prior to 1.0.1h openssl (prior to version 1.0.1h-r1)
Description The issue is related to multiple vulnerabilities in the OpenSSL package, which can lead to disruption of confidentiality, integrity, and availability of protected information. Exploitation of these vulnerabilities can be done remotely. The dtls1 reassemble fragment function in d1 both.c does not properly validate fragment lengths in DTLS ClientHello messages, allowing remote attackers to execute arbitrary code or cause a denial of service.
Recommendations For versions prior to 0.9.8za, update to version 0.9.8za or later. For versions prior to 1.0.0m, update to version 1.0.0m or later. For versions prior to 1.0.1h, update to version 1.0.1h or later. For openssl prior to version 1.0.1h-r1, update to version 1.0.1h-r1 or later. As a temporary workaround, consider disabling the dtls1 reassemble fragment function until a patch is available. Restrict access to the DTLS ClientHello messages to minimize the risk of exploitation. Avoid using the dtls1 reassemble fragment function in the affected API endpoint until the issue is resolved.

Exploit

Fix

RCE

DoS

NULL Pointer Dereference

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
BDU:2015-00144
BDU:2015-00145
BDU:2015-00643
BDU:2015-05844
BDU:2015-05845
BDU:2015-05846
BDU:2015-05847
BDU:2015-05848
BDU:2015-05849
BDU:2015-05850
BDU:2015-05851
BDU:2015-05852
BDU:2015-05853
BDU:2015-05854
BDU:2015-05855
BDU:2015-09698
CESA-2014_0625
CVE-2014-0195
DLA-0003-1
DSA-2950-1
ELSA-2014-0625
ELSA-2014-0679
HPSBUX03046
MGASA-2014-0255
OPENSUSE-SU-2014_0764-1
OPENSUSE-SU-2014_0765-1
OPENSUSE-SU-2016_0640-1
OPENSUSE-SU-2024:10271-1
OPENSUSE-SU-2024:10529-1
OPENSUSE-SU-2024:11127-1
RHSA-2014:0625
RHSA-2014:0628
RHSA-2014:0679
RHSA-2014_0625
RHSA-2014_0679
SUSE-FU-2022:0445-1
SUSE-RU-2015:0769-1
SUSE-SU-2014_0762-1
SUSE-SU-2015:0546-1
SUSE-SU-2015:0743-1
SUSE-SU-2015:1185-1
SUSE-SU-2015_0743-1
USN-2232-1
USN-2232-2
USN-2232-3
ZDI-14-173

Affected Products

Centos
Cisco Ios
Hp-Ux
Huawei Vrp
Ibm Aix
Mariadb Server
Openssl
Red Hat
Suse
Ubuntu