CVE-2014-0198NULL Pointer Dereference in Openssl

Severity
4.3MEDIUMNVD
OSV4.0
EPSS
33.0%
top 3.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 6
Latest updateMay 14

Description

The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, does not properly manage a buffer pointer during certain recursive calls, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors that trigger an alert condition.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages9 packages

Debianopenssl/openssl< 1.0.1g-4+3
Ubuntuopenssl/openssl< 1.0.1f-1ubuntu2.1
NVDopenssl/openssl1.0.01.0.1g
NVDmariadb/mariadb10.0.010.0.13
NVDopensuse/opensuse12.3, 13.1+1

Also affects: Debian Linux 6.0, 7.0, 8.0, Fedora 19, 20

Patches

🔴Vulnerability Details

4
GHSA
GHSA-f647-2p86-g4x9: The do_ssl3_write function in s3_pkt2022-05-14
OSV
CVE-2014-0198: The do_ssl3_write function in s3_pkt2014-05-06
CVEList
CVE-2014-0198: The do_ssl3_write function in s3_pkt2014-05-06
OSV
openssl vulnerabilities2014-05-05

📋Vendor Advisories

5
Cisco
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products2014-06-05
BSD
FreeBSD-SA-14:10.openssl: OpenSSL NULL pointer deference vulnerability2014-05-13
Ubuntu
OpenSSL vulnerabilities2014-05-05
Red Hat
openssl: SSL_MODE_RELEASE_BUFFERS NULL pointer dereference in do_ssl3_write()2014-04-21
Debian
CVE-2014-0198: openssl - The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, when SSL_M...2014

💬Community

4
Bugzilla
CVE-2014-0221 CVE-2014-0198 CVE-2014-0224 CVE-2014-0195 CVE-2010-5298 CVE-2014-3470 mingw-openssl: various flaws [epel-7]2014-08-07
Bugzilla
CVE-2014-0221 CVE-2014-0198 CVE-2014-0224 CVE-2014-0195 CVE-2010-5298 CVE-2014-3470 openssl: various flaws [fedora-all]2014-05-09
Bugzilla
CVE-2014-0221 CVE-2014-0198 CVE-2014-0224 CVE-2014-0195 CVE-2010-5298 CVE-2014-3470 mingw-openssl: various flaws [fedora-all]2014-05-09
Bugzilla
CVE-2014-0198 openssl: SSL_MODE_RELEASE_BUFFERS NULL pointer dereference in do_ssl3_write()2014-05-02
CVE-2014-0198 — NULL Pointer Dereference in Openssl | cvebase