Lucene search

K
opensslOpenSSLOPENSSL:CVE-2014-3507
HistoryAug 06, 2014 - 12:00 a.m.

Vulnerability in OpenSSL - DTLS memory leak from zero-length fragments

2014-08-0600:00:00
www.openssl-library.org
33

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

AI Score

5.6

Confidence

High

EPSS

0.919

Percentile

99.0%

A DTLS memory leak from zero-length fragments was found. By sending carefully crafted DTLS packets an attacker could cause OpenSSL to leak memory. This could lead to a Denial of Service attack.

Found by Adam Langley (Google).

Affected configurations

Vulners
Node
opensslopensslRange1.0.1โ€“1.0.1i
OR
opensslopensslRange1.0.0aโ€“1.0.0n
OR
opensslopensslRange0.9.8oโ€“0.9.8zb
VendorProductVersionCPE
opensslopenssl*cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

AI Score

5.6

Confidence

High

EPSS

0.919

Percentile

99.0%