CVE-2011-0014
published 2011-02-19CVE-2011-0014: ssl/t1_lib.c in OpenSSL 0.9.8h through 0.9.8q and 1.0.0 through 1.0.0c allows remote attackers to cause a denial of service (crash), and possibly obtain…
PriorityP427medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
9.85%
95.0th percentile
ssl/t1_lib.c in OpenSSL 0.9.8h through 0.9.8q and 1.0.0 through 1.0.0c allows remote attackers to cause a denial of service (crash), and possibly obtain sensitive information in applications that use OpenSSL, via a malformed ClientHello handshake message that triggers an out-of-bounds memory access, aka "OCSP stapling vulnerability."
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openssl | < openssl 0.9.8o-5 (bookworm) | openssl 0.9.8o-5 (bookworm) |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | >= 0 < 0.9.8o-5 | 0.9.8o-5 |
| openssl | openssl | >= 0 < 0.9.8o-5 | 0.9.8o-5 |
| openssl | openssl | >= 0 < 0.9.8o-5 | 0.9.8o-5 |
| openssl | openssl | >= 0 < 0.9.8o-5 | 0.9.8o-5 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenSSL vulnerability
vendor_ubuntu·2011-02-15
CVE-2011-0014 OpenSSL vulnerability
Title: OpenSSL vulnerability
Neel Mehta discovered that incorrectly formatted ClientHello handshake
messages could cause OpenSSL to parse past the end of the message.
This could allow a remote attacker to cause a crash and denial of
service by triggering invalid memory accesses.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
openssl: OCSP stapling vulnerability
vendor_redhat·2011-02-08·CVSS 5.0
CVE-2011-0014 [MEDIUM] openssl: OCSP stapling vulnerability
openssl: OCSP stapling vulnerability
ssl/t1_lib.c in OpenSSL 0.9.8h through 0.9.8q and 1.0.0 through 1.0.0c allows remote attackers to cause a denial of service (crash), and possibly obtain sensitive information in applications that use OpenSSL, via a malformed ClientHello handshake message that triggers an out-of-bounds memory access, aka "OCSP stapling vulnerability."
Statement: This issue did not affect the versions of openssl as shipped with Red Hat Enterprise Linux 3, 4, and 5. It was addressed in Red Hat Enterprise Linux 6 via RHSA-2011:0677.
Package: openssl (Red Hat Enterprise Linux 4) - Not affected
Package: openssl (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2011-0014: openssl - ssl/t1_lib.c in OpenSSL 0.9.8h through 0.9.8q and 1.0.0 through 1.0.0c allows re...
vendor_debian·2011·CVSS 5.0
CVE-2011-0014 [MEDIUM] CVE-2011-0014: openssl - ssl/t1_lib.c in OpenSSL 0.9.8h through 0.9.8q and 1.0.0 through 1.0.0c allows re...
ssl/t1_lib.c in OpenSSL 0.9.8h through 0.9.8q and 1.0.0 through 1.0.0c allows remote attackers to cause a denial of service (crash), and possibly obtain sensitive information in applications that use OpenSSL, via a malformed ClientHello handshake message that triggers an out-of-bounds memory access, aka "OCSP stapling vulnerability."
Scope: local
bookworm: resolved (fixed in 0.9.8o-5)
bullseye: resolved (fixed in 0.9.8o-5)
forky: resolved (fixed in 0.9.8o-5)
sid: resolved (fixed in 0.9.8o-5)
trixie: resolved (fixed in 0.9.8o-5)
GHSA
GHSA-w2hr-4cx4-4hmj: ssl/t1_lib
ghsa_unreviewed·2022-05-03
CVE-2011-0014 [MEDIUM] GHSA-w2hr-4cx4-4hmj: ssl/t1_lib
ssl/t1_lib.c in OpenSSL 0.9.8h through 0.9.8q and 1.0.0 through 1.0.0c allows remote attackers to cause a denial of service (crash), and possibly obtain sensitive information in applications that use OpenSSL, via a malformed ClientHello handshake message that triggers an out-of-bounds memory access, aka "OCSP stapling vulnerability."
OSV
CVE-2011-0014: ssl/t1_lib
osv·2011-02-19·CVSS 5.0
CVE-2011-0014 [MEDIUM] CVE-2011-0014: ssl/t1_lib
ssl/t1_lib.c in OpenSSL 0.9.8h through 0.9.8q and 1.0.0 through 1.0.0c allows remote attackers to cause a denial of service (crash), and possibly obtain sensitive information in applications that use OpenSSL, via a malformed ClientHello handshake message that triggers an out-of-bounds memory access, aka "OCSP stapling vulnerability."
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-0014 openssl: OCSP stapling vulnerability
bugzilla·2011-02-08·CVSS 5.0
CVE-2011-0014 [MEDIUM] CVE-2011-0014 openssl: OCSP stapling vulnerability
CVE-2011-0014 openssl: OCSP stapling vulnerability
A flaw [1] was found in OpenSSL 0.9.8h through 0.9.8q and 1.0.0 through 1.0.0c where an incorrectly formatted ClientHello handshake message could cause OpenSSL to parse past the end of the message. An attacker could use this flaw to trigger an invalid memory access, causing a crash of an application linked to OpenSSL. As well, certain applications may expose the contents of parsed OCSP extensions, specifically the OCSP nonce extension.
Applications are only affected if they act as a server and call SSL_CTX_set_tlsext_status_cb on the server's SSL_CTX. One such application is Apache httpd >= 2.3.3.
This issue was addressed in OpenSSL versions 0.9.8r and 1.0.0d. A patch is included in the upstream advisory [1].
[1] http://www.openssl.org
Bugzilla
CVE-2011-0014 openssl: OCSP stapling vulnerability [fedora-all]
bugzilla·2011-02-08·CVSS 5.0
CVE-2011-0014 [MEDIUM] CVE-2011-0014 openssl: OCSP stapling vulnerability [fedora-all]
CVE-2011-0014 openssl: OCSP stapling vulnerability [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=676063
Please note: this issue affects multiple supported
Bugzilla
CVE-2011-0014 openssl: OCSP stapling vulnerability [fedora-all]
bugzilla·2011-02-08·CVSS 5.0
CVE-2011-0014 [MEDIUM] CVE-2011-0014 openssl: OCSP stapling vulnerability [fedora-all]
CVE-2011-0014 openssl: OCSP stapling vulnerability [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=676063
Please note: this issue affects multiple supported
arXiv
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
arxiv_fulltext·2022-12-29
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
## Abstract
Currently, the development of IoT firmware heavily depends on third-party components (TPCs) to improve development efficiency. Nevertheless, TPCs are not secure, and the vulnerabilities in TPCs will influence the security of IoT firmware. Existing works pay less attention to the vulnerabilities caused by TPCs, and we still lack a comprehensive understanding of the security impact of TPC vulnerability against firmware. To fill in the knowledge gap, we design and implement , which leverages syntactical features and control-flow graph features to detect the TPCs in firmware, and then recognizes the corresponding vulnerabilities. Based on , we present the first l
http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2011-002.txt.aschttp://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02794777http://lists.apple.com/archives/security-announce/2011//Jun/msg00000.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-February/054007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-04/msg00000.htmlhttp://marc.info/?l=bugtraq&m=130497251507577&w=2http://marc.info/?l=bugtraq&m=131042179515633&w=2http://osvdb.org/70847http://secunia.com/advisories/43227http://secunia.com/advisories/43286http://secunia.com/advisories/43301http://secunia.com/advisories/43339http://secunia.com/advisories/44269http://secunia.com/advisories/57353http://slackware.com/security/viewer.php?l=slackware-security&y=2011&m=slackware-security.668823http://support.apple.com/kb/HT4723http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004564http://www.debian.org/security/2011/dsa-2162http://www.mandriva.com/security/advisories?name=MDVSA-2011:028http://www.openssl.org/news/secadv_20110208.txthttp://www.redhat.com/support/errata/RHSA-2011-0677.htmlhttp://www.securityfocus.com/bid/46264http://www.securitytracker.com/id?1025050http://www.ubuntu.com/usn/USN-1064-1http://www.vupen.com/english/advisories/2011/0361http://www.vupen.com/english/advisories/2011/0387http://www.vupen.com/english/advisories/2011/0389http://www.vupen.com/english/advisories/2011/0395http://www.vupen.com/english/advisories/2011/0399http://www.vupen.com/english/advisories/2011/0603https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18985https://support.f5.com/csp/article/K10534046http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2011-002.txt.aschttp://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02794777http://lists.apple.com/archives/security-announce/2011//Jun/msg00000.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-February/054007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-04/msg00000.htmlhttp://marc.info/?l=bugtraq&m=130497251507577&w=2http://marc.info/?l=bugtraq&m=131042179515633&w=2http://osvdb.org/70847http://secunia.com/advisories/43227http://secunia.com/advisories/43286http://secunia.com/advisories/43301http://secunia.com/advisories/43339http://secunia.com/advisories/44269http://secunia.com/advisories/57353http://slackware.com/security/viewer.php?l=slackware-security&y=2011&m=slackware-security.668823http://support.apple.com/kb/HT4723http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004564http://www.debian.org/security/2011/dsa-2162http://www.mandriva.com/security/advisories?name=MDVSA-2011:028http://www.openssl.org/news/secadv_20110208.txthttp://www.redhat.com/support/errata/RHSA-2011-0677.htmlhttp://www.securityfocus.com/bid/46264http://www.securitytracker.com/id?1025050http://www.ubuntu.com/usn/USN-1064-1http://www.vupen.com/english/advisories/2011/0361http://www.vupen.com/english/advisories/2011/0387http://www.vupen.com/english/advisories/2011/0389http://www.vupen.com/english/advisories/2011/0395http://www.vupen.com/english/advisories/2011/0399http://www.vupen.com/english/advisories/2011/0603https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18985https://support.f5.com/csp/article/K10534046
2011-02-19
Published