Lucene search

K
cveRedhatCVE-2014-3510
HistoryAug 13, 2014 - 11:55 p.m.

CVE-2014-3510

2014-08-1323:55:07
redhat
web.nvd.nist.gov
88
openssl
vulnerability
remote
denial of service
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

AI Score

5.5

Confidence

Low

EPSS

0.016

Percentile

87.4%

The ssl3_send_client_key_exchange function in s3_clnt.c in OpenSSL 0.9.8 before 0.9.8zb, 1.0.0 before 1.0.0n, and 1.0.1 before 1.0.1i allows remote DTLS servers to cause a denial of service (NULL pointer dereference and client application crash) via a crafted handshake message in conjunction with a (1) anonymous DH or (2) anonymous ECDH ciphersuite.

Affected configurations

Nvd
Node
opensslopensslMatch0.9.8
OR
opensslopensslMatch0.9.8a
OR
opensslopensslMatch0.9.8b
OR
opensslopensslMatch0.9.8c
OR
opensslopensslMatch0.9.8d
OR
opensslopensslMatch0.9.8e
OR
opensslopensslMatch0.9.8f
OR
opensslopensslMatch0.9.8g
OR
opensslopensslMatch0.9.8h
OR
opensslopensslMatch0.9.8i
OR
opensslopensslMatch0.9.8j
OR
opensslopensslMatch0.9.8k
OR
opensslopensslMatch0.9.8l
OR
opensslopensslMatch0.9.8m
OR
opensslopensslMatch0.9.8mbeta1
OR
opensslopensslMatch0.9.8n
OR
opensslopensslMatch0.9.8o
OR
opensslopensslMatch0.9.8p
OR
opensslopensslMatch0.9.8q
OR
opensslopensslMatch0.9.8r
OR
opensslopensslMatch0.9.8s
OR
opensslopensslMatch0.9.8t
OR
opensslopensslMatch0.9.8u
OR
opensslopensslMatch0.9.8v
OR
opensslopensslMatch0.9.8w
OR
opensslopensslMatch0.9.8x
OR
opensslopensslMatch0.9.8y
OR
opensslopensslMatch0.9.8za
OR
opensslopensslMatch1.0.0
OR
opensslopensslMatch1.0.0beta1
OR
opensslopensslMatch1.0.0beta2
OR
opensslopensslMatch1.0.0beta3
OR
opensslopensslMatch1.0.0beta4
OR
opensslopensslMatch1.0.0beta5
OR
opensslopensslMatch1.0.0a
OR
opensslopensslMatch1.0.0b
OR
opensslopensslMatch1.0.0c
OR
opensslopensslMatch1.0.0d
OR
opensslopensslMatch1.0.0e
OR
opensslopensslMatch1.0.0f
OR
opensslopensslMatch1.0.0g
OR
opensslopensslMatch1.0.0h
OR
opensslopensslMatch1.0.0i
OR
opensslopensslMatch1.0.0j
OR
opensslopensslMatch1.0.0k
OR
opensslopensslMatch1.0.0l
OR
opensslopensslMatch1.0.0m
OR
opensslopensslMatch1.0.1
OR
opensslopensslMatch1.0.1beta1
OR
opensslopensslMatch1.0.1beta2
OR
opensslopensslMatch1.0.1beta3
OR
opensslopensslMatch1.0.1a
OR
opensslopensslMatch1.0.1b
OR
opensslopensslMatch1.0.1c
OR
opensslopensslMatch1.0.1d
OR
opensslopensslMatch1.0.1e
OR
opensslopensslMatch1.0.1f
OR
opensslopensslMatch1.0.1g
OR
opensslopensslMatch1.0.1h
VendorProductVersionCPE
opensslopenssl0.9.8cpe:2.3:a:openssl:openssl:0.9.8:*:*:*:*:*:*:*
opensslopenssl0.9.8acpe:2.3:a:openssl:openssl:0.9.8a:*:*:*:*:*:*:*
opensslopenssl0.9.8bcpe:2.3:a:openssl:openssl:0.9.8b:*:*:*:*:*:*:*
opensslopenssl0.9.8ccpe:2.3:a:openssl:openssl:0.9.8c:*:*:*:*:*:*:*
opensslopenssl0.9.8dcpe:2.3:a:openssl:openssl:0.9.8d:*:*:*:*:*:*:*
opensslopenssl0.9.8ecpe:2.3:a:openssl:openssl:0.9.8e:*:*:*:*:*:*:*
opensslopenssl0.9.8fcpe:2.3:a:openssl:openssl:0.9.8f:*:*:*:*:*:*:*
opensslopenssl0.9.8gcpe:2.3:a:openssl:openssl:0.9.8g:*:*:*:*:*:*:*
opensslopenssl0.9.8hcpe:2.3:a:openssl:openssl:0.9.8h:*:*:*:*:*:*:*
opensslopenssl0.9.8icpe:2.3:a:openssl:openssl:0.9.8i:*:*:*:*:*:*:*
Rows per page:
1-10 of 591

References

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

AI Score

5.5

Confidence

Low

EPSS

0.016

Percentile

87.4%