Lucene search

K
opensslOpenSSLOPENSSL:CVE-2014-3506
HistoryAug 06, 2014 - 12:00 a.m.

Vulnerability in OpenSSL - DTLS memory exhaustion

2014-08-0600:00:00
www.openssl-library.org
33

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

AI Score

5.7

Confidence

Low

EPSS

0.863

Percentile

98.6%

A DTLS flaw leading to memory exhaustion was found. An attacker can force openssl to consume large amounts of memory whilst processing DTLS handshake messages. This could lead to a Denial of Service attack.

Found by Adam Langley (Google).

Affected configurations

Vulners
Node
opensslopensslRange1.0.1โ€“1.0.1i
OR
opensslopensslRange1.0.0โ€“1.0.0n
OR
opensslopensslRange0.9.8โ€“0.9.8zb
VendorProductVersionCPE
opensslopenssl*cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

AI Score

5.7

Confidence

Low

EPSS

0.863

Percentile

98.6%