CVE-2014-0198
The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, does not properly manage a buffer pointer during certain recursive calls, which allows remote attackers to cause a denial of service (NULL…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 43.8%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, does not properly manage a buffer pointer during certain recursive calls, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors that trigger an alert condition.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
- EPSS
- 43.83% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-476
- Affected
- openssl/openssl · mariadb/mariadb · fedoraproject/fedora · debian/debian linux · opensuse/opensuse · suse/linux enterprise desktop · suse/linux enterprise server · suse/linux enterprise software development kit · suse/linux enterprise workstation extension
- Source
- secalert@redhat.com
References
- http://advisories.mageia.org/MGASA-2014-0204.htmlThird Party Advisory
- http://aix.software.ibm.com/aix/efixes/security/openssl_advisory9.ascThird Party Advisory
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10629Third Party Advisory
- http://kb.juniper.net/InfoCenter/index?page=content&id=KB29195Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136470.htmlMailing List, Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136473.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00016.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2014-05/msg00036.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2014-05/msg00037.htmlMailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=140389274407904&w=2Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=140389355508263&w=2Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=140431828824371&w=2Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=140448122410568&w=2Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=140544599631400&w=2Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=140621259019789&w=2Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=140752315422991&w=2Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=140904544427729&w=2Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=141658880509699&w=2Mailing List, Third Party Advisory
- http://puppetlabs.com/security/cve/cve-2014-0198Third Party Advisory
- http://seclists.org/fulldisclosure/2014/Dec/23Mailing List, Third Party Advisory
- http://secunia.com/advisories/58337Not Applicable
- http://secunia.com/advisories/58667Not Applicable
- http://secunia.com/advisories/58713Not Applicable
- http://secunia.com/advisories/58714Not Applicable
- http://secunia.com/advisories/58939Not Applicable
- http://secunia.com/advisories/58945Not Applicable
- http://secunia.com/advisories/58977Not Applicable
- http://secunia.com/advisories/59126Not Applicable
- http://secunia.com/advisories/59162Not Applicable
- http://secunia.com/advisories/59163Not Applicable
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.