CVE-2014-0160
OpenSSL Information Disclosure Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 25 May 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 100.00% probability · 100th percentile
- CISA KEV
- Listed 4 May 2022 · due 25 May 2022
- Weakness
- CWE-125
- Affected
- openssl/openssl · filezilla-project/filezilla server · siemens/application processing engine firmware · siemens/cp 1543-1 firmware · siemens/simatic s7-1500 firmware · siemens/simatic s7-1500t firmware · siemens/elan-8.2 · siemens/wincc open architecture · intellian/v100 firmware · intellian/v60 firmware · mitel/micollab · mitel/mivoice · opensuse/opensuse · canonical/ubuntu linux · fedoraproject/fedora · redhat/gluster storage · redhat/storage · redhat/virtualization · redhat/enterprise linux desktop · redhat/enterprise linux server · +8 more
- Source
- secalert@redhat.com
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2014-0160
References
- http://advisories.mageia.org/MGASA-2014-0165.htmlThird Party Advisory
- http://blog.fox-it.com/2014/04/08/openssl-heartbleed-bug-live-blog/Issue Tracking, Third Party Advisory
- http://cogentdatahub.com/ReleaseNotes.htmlRelease Notes
- http://download.schneider-electric.com/files?p_Doc_Ref=SEVD%202014-119-01Broken Link
- http://git.openssl.org/gitweb/?p=openssl.git%3Ba=commit%3Bh=96db9023b881d7cd9f379b0c154650d6c108e9a3Broken Link
- http://heartbleed.com/Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2014-April/131221.htmlBroken Link, Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2014-April/131291.htmlBroken Link, Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136473.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2014-04/msg00004.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2014-04/msg00005.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2014-04/msg00061.htmlMailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=139722163017074&w=2Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=139757726426985&w=2Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=139757819327350&w=2Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=139757919027752&w=2Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=139758572430452&w=2Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=139765756720506&w=2Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=139774054614965&w=2Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=139774703817488&w=2Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=139808058921905&w=2Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=139817685517037&w=2Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=139817727317190&w=2Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=139817782017443&w=2Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=139824923705461&w=2Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=139824993005633&w=2Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=139833395230364&w=2Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=139835815211508&w=2Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=139835844111589&w=2Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=139836085512508&w=2Mailing List, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.