Lucene search

K
opensslOpenSSLOPENSSL:CVE-2014-0221
HistoryJun 05, 2014 - 12:00 a.m.

Vulnerability in OpenSSL - DTLS recursion flaw

2014-06-0500:00:00
www.openssl-library.org
35

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

AI Score

7.2

Confidence

High

EPSS

0.964

Percentile

99.6%

By sending an invalid DTLS handshake to an OpenSSL DTLS client the code can be made to recurse eventually crashing in a DoS attack. Only applications using OpenSSL as a DTLS client are affected.

Found by Imre Rad (Search-Lab Ltd.).

Affected configurations

Vulners
Node
opensslopensslRange1.0.11.0.1h
OR
opensslopensslRange1.0.01.0.0m
OR
opensslopensslRange0.9.80.9.8za
VendorProductVersionCPE
opensslopenssl*cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

AI Score

7.2

Confidence

High

EPSS

0.964

Percentile

99.6%