Lucene search

K
opensslOpenSSLOPENSSL:CVE-2014-8176
HistoryJun 11, 2015 - 12:00 a.m.

Vulnerability in OpenSSL - Invalid free in DTLS

2015-06-1100:00:00
www.openssl-library.org
20

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

6.6

Confidence

High

EPSS

0.04

Percentile

92.1%

This vulnerability does not affect current versions of OpenSSL. It existed in previous OpenSSL versions and was fixed in June 2014. If a DTLS peer receives application data between the ChangeCipherSpec and Finished messages, buffering of such data may cause an invalid free, resulting in a segmentation fault or potentially, memory corruption.

Found by Praveen Kariyanahalli, and subsequently by Ivan Fratric and Felix Groebert (Google).

Affected configurations

Vulners
Node
opensslopensslRange1.0.11.0.1h
OR
opensslopensslRange1.0.01.0.0m
OR
opensslopensslRange0.9.80.9.8za
VendorProductVersionCPE
opensslopenssl*cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

6.6

Confidence

High

EPSS

0.04

Percentile

92.1%