Lucene search

K
cvelistRedhatCVELIST:CVE-2014-3506
HistoryAug 13, 2014 - 11:00 p.m.

CVE-2014-3506

2014-08-1323:00:00
redhat
www.cve.org
8

AI Score

5.6

Confidence

High

EPSS

0.863

Percentile

98.6%

d1_both.c in the DTLS implementation in OpenSSL 0.9.8 before 0.9.8zb, 1.0.0 before 1.0.0n, and 1.0.1 before 1.0.1i allows remote attackers to cause a denial of service (memory consumption) via crafted DTLS handshake messages that trigger memory allocations corresponding to large length values.

References