SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2014-0198

The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, does not properly manage a buffer pointer during certain recursive calls, which allows remote attackers to cause a denial of service (NULL…

MEDIUM 4.3EPSS 43.8%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 43.8%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, does not properly manage a buffer pointer during certain recursive calls, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors that trigger an alert condition.

CVSS 2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
EPSS
43.83% probability · 99th percentile
CISA KEV
Not listed
Weakness
CWE-476
Affected
openssl/openssl · mariadb/mariadb · fedoraproject/fedora · debian/debian linux · opensuse/opensuse · suse/linux enterprise desktop · suse/linux enterprise server · suse/linux enterprise software development kit · suse/linux enterprise workstation extension
Source
secalert@redhat.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.