CVE-2014-3566
The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 100.0%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.
- CVSS 3.1
- 3.4 LOWCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N
- EPSS
- 100.00% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-310, CWE-329
- Affected
- redhat/enterprise linux · redhat/enterprise linux desktop · redhat/enterprise linux desktop supplementary · redhat/enterprise linux server · redhat/enterprise linux server supplementary · redhat/enterprise linux workstation · redhat/enterprise linux workstation supplementary · ibm/aix · apple/mac os x · mageia/mageia · novell/suse linux enterprise desktop · novell/suse linux enterprise software development kit · novell/suse linux enterprise server · opensuse/opensuse · fedoraproject/fedora · openssl/openssl · ibm/vios · netbsd/netbsd · debian/debian linux · oracle/database
- Source
- secalert@redhat.com
References
- ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2014-015.txt.ascThird Party Advisory
- http://advisories.mageia.org/MGASA-2014-0416.htmlThird Party Advisory
- http://aix.software.ibm.com/aix/efixes/security/openssl_advisory11.ascThird Party Advisory
- http://archives.neohapsis.com/archives/bugtraq/2014-10/0101.htmlThird Party Advisory
- http://archives.neohapsis.com/archives/bugtraq/2014-10/0103.htmlThird Party Advisory
- http://askubuntu.com/questions/537196/how-do-i-patch-workaround-sslv3-poodle-vulnerability-cve-2014-3566Third Party Advisory
- http://blog.cryptographyengineering.com/2014/10/attack-of-week-poodle.htmlThird Party Advisory
- http://blog.nodejs.org/2014/10/23/node-v0-10-33-stable/Third Party Advisory
- http://blogs.technet.com/b/msrc/archive/2014/10/14/security-advisory-3009008-released.aspxThird Party Advisory
- http://docs.ipswitch.com/MOVEit/DMZ82/ReleaseNotes/MOVEitReleaseNotes82.pdfThird Party Advisory
- http://downloads.asterisk.org/pub/security/AST-2014-011.htmlThird Party Advisory
- http://googleonlinesecurity.blogspot.com/2014/10/this-poodle-bites-exploiting-ssl-30.htmlThird Party Advisory
- http://h20564.www2.hp.com/hpsc/doc/public/display?docId=emr_na-c04583581Third Party Advisory
- http://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c04779034Third Party Advisory
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705Third Party Advisory
- http://lists.apple.com/archives/security-announce/2015/Jan/msg00003.htmlMailing List, Third Party Advisory
- http://lists.apple.com/archives/security-announce/2015/Sep/msg00002.htmlMailing List, Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2014-November/142330.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2014-October/141114.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2014-October/141158.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2015-October/169361.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2015-October/169374.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2014-10/msg00008.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2014-11/msg00001.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2014-11/msg00003.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2014-11/msg00021.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2014-12/msg00002.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00001.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00024.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00026.htmlThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.