CVE-2014-3470
The ssl3_send_client_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h, when an anonymous ECDH cipher suite is used, allows remote attackers to cause a denial of service (NULL pointer dereference…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 85.8%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
The ssl3_send_client_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h, when an anonymous ECDH cipher suite is used, allows remote attackers to cause a denial of service (NULL pointer dereference and client crash) by triggering a NULL certificate value.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
- EPSS
- 85.78% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-476
- Affected
- openssl/openssl · redhat/storage · fedoraproject/fedora · redhat/enterprise linux · mariadb/mariadb · opensuse/leap · opensuse/opensuse · suse/linux enterprise desktop · suse/linux enterprise server · suse/linux enterprise software development kit · suse/linux enterprise workstation extension
- Source
- secalert@redhat.com
References
- http://aix.software.ibm.com/aix/efixes/security/openssl_advisory9.ascThird Party Advisory
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10629Third Party Advisory
- http://kb.juniper.net/InfoCenter/index?page=content&id=KB29195Permissions Required, Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136470.htmlMailing List, Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136473.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00027.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00016.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.htmlMailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=140266410314613&w=2Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=140317760000786&w=2Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=140389274407904&w=2Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=140389355508263&w=2Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=140431828824371&w=2Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=140448122410568&w=2Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=140482916501310&w=2Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=140491231331543&w=2Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=140499827729550&w=2Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=140621259019789&w=2Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=140752315422991&w=2Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=140904544427729&w=2Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2014/Dec/23Mailing List, Third Party Advisory
- http://secunia.com/advisories/58337Not Applicable
- http://secunia.com/advisories/58579Not Applicable
- http://secunia.com/advisories/58615Not Applicable
- http://secunia.com/advisories/58667Not Applicable
- http://secunia.com/advisories/58713Not Applicable
- http://secunia.com/advisories/58714Not Applicable
- http://secunia.com/advisories/58716Not Applicable
- http://secunia.com/advisories/58742Not Applicable
- http://secunia.com/advisories/58797Not Applicable
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.