CVE-2014-0198
published 2014-05-06CVE-2014-0198: The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, does not properly manage a buffer pointer…
PriorityP432medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
43.83%
98.6th percentile
The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, does not properly manage a buffer pointer during certain recursive calls, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors that trigger an alert condition.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | products | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | openssl | < openssl 1.0.1g-4 (bookworm) | openssl 1.0.1g-4 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| mariadb | mariadb | >= 10.0.0 < 10.0.13 | 10.0.13 |
| openssl | openssl | >= 0 < 1.0.1g-4 | 1.0.1g-4 |
| openssl | openssl | >= 0 < 1.0.1g-4 | 1.0.1g-4 |
| openssl | openssl | >= 0 < 1.0.1g-4 | 1.0.1g-4 |
| openssl | openssl | >= 0 < 1.0.1g-4 | 1.0.1g-4 |
| openssl | openssl | >= 0 < 1.0.1f-1ubuntu2.1 | 1.0.1f-1ubuntu2.1 |
| openssl | openssl | 1.0.0 – 1.0.1g | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_software_development_kit | — | — |
| suse | linux_enterprise_workstation_extension | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_cisco10.0CRITICAL
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
vendor_ubuntu4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Rockwell Automation Stratix 5900
cisa_ics·2017-05-10
Rockwell Automation Stratix 5900
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Rockwell Automation Stratix 5900
Last RevisedMay 10, 2017
Alert CodeICSA-17-094-04
## CVSS v3 10.0
ATTENTION: Remotely exploitable/low skill level to exploit.
Vendor: Rockwell Automation
Equipment: Stratix 5900
Vulnerabilities: Improper Input Validation, Resource Management Errors, Improper Authentication, Path Traversal.
## REPOSTED INFORMATION
This advisory was originally posted to the NCCIC Portal on April 4, 2017, and is being released to the NCCIC/ICS-CERT web site.
## AFFECTED PRODUCTS
Rockwell Automation reports that these vulnerabilities affect the following Strat
CISA ICS
Siemens OpenSSL Vulnerabilities (Update G)
cisa_ics·2014-10-16
Siemens OpenSSL Vulnerabilities (Update G)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens OpenSSL Vulnerabilities (Update G)
Last RevisedAugust 29, 2018
Alert CodeICSA-14-198-03G
## OVERVIEW
This updated advisory is a follow-up to the updated advisory titled ICSA-14-198-03F Siemens OpenSSL Vulnerabilities that was published October 16, 2014, on the NCCIC/ICS-CERT web site.
## --------- Begin Update G Part 1 of 3 --------
Siemens has identified four vulnerabilities in its OpenSSL cryptographic software library affecting several Siemens industrial products. Updates are available for APE 2.0.2, S7-1500, WinCC OA (PVSS), CP1543-1, Ruggedcom ROX 1, and ROX 2-bas
Cisco
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products
vendor_cisco·2014-06-05·CVSS 10.0
CVE-2010-5298 [CRITICAL] Multiple Vulnerabilities in OpenSSL Affecting Cisco Products
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products
Multiple Cisco products incorporate a version of the OpenSSL package affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to execute arbitrary code, create a denial of service (DoS) condition, or perform a man-in-the-middle attack. On June 5, 2014, the OpenSSL Project released a security advisory detailing seven distinct vulnerabilities. The vulnerabilities are referenced in this document as follows:
SSL/TLS Man-in-the-Middle Vulnerability
DTLS Recursion Flaw Vulnerability
DTLS Invalid Fragment Vulnerability
SSL_MODE_RELEASE_BUFFERS NULL Pointer Dereference Vulnerability
SSL_MODE_RELEASE_BUFFERS Session Injection or Denial of Service Vulnerability
Anonymous ECDH Denial of Service Vulnerab
BSD
FreeBSD-SA-14:10.openssl: OpenSSL NULL pointer deference vulnerability
bsd_advisories·2014-05-13·CVSS 4.3
CVE-2014-0198 [MEDIUM] FreeBSD-SA-14:10.openssl: OpenSSL NULL pointer deference vulnerability
FreeBSD-SA-14:10.openssl Security Advisory
The FreeBSD Project
Topic: OpenSSL NULL pointer deference vulnerability
Category: contrib
Module: openssl
Announced: 2014-05-13
Affects: FreeBSD 10.x.
Corrected: 2014-05-13 23:19:16 UTC (stable/10, 10.0-STABLE)
2014-05-13 23:22:28 UTC (releng/10.0, 10.0-RELEASE-p3)
CVE Name: CVE-2014-0198
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit .
I. Background
FreeBSD includes software from the OpenSSL Project. The OpenSSL Project is
a collaborative effort to develop a robust, commercial-grade, full-featured
Open Source toolkit implementing the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols as well as
Ubuntu
OpenSSL vulnerabilities
vendor_ubuntu·2014-05-05·CVSS 4.0
CVE-2010-5298 [MEDIUM] OpenSSL vulnerabilities
Title: OpenSSL vulnerabilities
Summary: OpenSSL could be made to crash if it received specially crafted network
traffic.
It was discovered that OpenSSL incorrectly handled memory in the
ssl3_read_bytes() function. A remote attacker could use this issue to
possibly cause OpenSSL to crash, resulting in a denial of service.
(CVE-2010-5298)
It was discovered that OpenSSL incorrectly handled memory in the
do_ssl3_write() function. A remote attacker could use this issue to
possibly cause OpenSSL to crash, resulting in a denial of service.
(CVE-2014-0198)
Instructions: After a standard system update you need to reboot your computer to make all
the necessary changes.
Red Hat
openssl: SSL_MODE_RELEASE_BUFFERS NULL pointer dereference in do_ssl3_write()
vendor_redhat·2014-04-21·CVSS 4.3
CVE-2014-0198 [MEDIUM] CWE-476 openssl: SSL_MODE_RELEASE_BUFFERS NULL pointer dereference in do_ssl3_write()
openssl: SSL_MODE_RELEASE_BUFFERS NULL pointer dereference in do_ssl3_write()
The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, does not properly manage a buffer pointer during certain recursive calls, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors that trigger an alert condition.
Statement: This issue did not affect the openssl packages shipped with Red Hat Enterprise Linux 5.
Package: openssl (Red Hat Enterprise Linux 5) - Not affected
Package: openssl097a (Red Hat Enterprise Linux 5) - Not affected
Package: guest-images (Red Hat Enterprise Linux 6) - Not affected
Package: openssl098e (Red Hat Enterprise Linux 6) - Not affected
Package: openssl098e
Debian
CVE-2014-0198: openssl - The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, when SSL_M...
vendor_debian·2014·CVSS 4.3
CVE-2014-0198 [MEDIUM] CVE-2014-0198: openssl - The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, when SSL_M...
The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, does not properly manage a buffer pointer during certain recursive calls, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors that trigger an alert condition.
Scope: local
bookworm: resolved (fixed in 1.0.1g-4)
bullseye: resolved (fixed in 1.0.1g-4)
forky: resolved (fixed in 1.0.1g-4)
sid: resolved (fixed in 1.0.1g-4)
trixie: resolved (fixed in 1.0.1g-4)
Cisco
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products
vendor_cisco
CVE-2014-0198 Multiple Vulnerabilities in OpenSSL Affecting Cisco Products
CVE-2014-0198: Multiple Vulnerabilities in OpenSSL Affecting Cisco Products
Multiple Cisco products incorporate a version of the OpenSSL package affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to execute arbitrary code, create a denial of service (DoS) condition, or perform a man-in-the-middle attack. On June 5, 2014, the OpenSSL Project released a security advisory detailing seven distinct vulnerabilities. The vulnerabilities are referenced in this document as follows: SSL/TLS Man-in-the-Middle Vulnerability DTLS Recursion Flaw Vulnerability DTLS Invalid Fragment Vulnerability SSL_MODE_RELEASE_BUFFERS NULL Pointer Dereference Vulnerability SSL_MODE_RELEASE_BUFFERS Session Injection or Denial of Service Vulnerability Anonymous ECDH Denial of Ser
GHSA
GHSA-f647-2p86-g4x9: The do_ssl3_write function in s3_pkt
ghsa_unreviewed·2022-05-14
CVE-2014-0198 [MEDIUM] CWE-476 GHSA-f647-2p86-g4x9: The do_ssl3_write function in s3_pkt
The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, does not properly manage a buffer pointer during certain recursive calls, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors that trigger an alert condition.
OSV
CVE-2014-0198: The do_ssl3_write function in s3_pkt
osv·2014-05-06·CVSS 4.3
CVE-2014-0198 [MEDIUM] CVE-2014-0198: The do_ssl3_write function in s3_pkt
The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, does not properly manage a buffer pointer during certain recursive calls, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors that trigger an alert condition.
OSV
openssl vulnerabilities
osv·2014-05-05·CVSS 4.0
CVE-2010-5298 [MEDIUM] openssl vulnerabilities
openssl vulnerabilities
It was discovered that OpenSSL incorrectly handled memory in the
ssl3_read_bytes() function. A remote attacker could use this issue to
possibly cause OpenSSL to crash, resulting in a denial of service.
(CVE-2010-5298)
It was discovered that OpenSSL incorrectly handled memory in the
do_ssl3_write() function. A remote attacker could use this issue to
possibly cause OpenSSL to crash, resulting in a denial of service.
(CVE-2014-0198)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-0221 CVE-2014-0198 CVE-2014-0224 CVE-2014-0195 CVE-2010-5298 CVE-2014-3470 mingw-openssl: various flaws [epel-7]
bugzilla·2014-08-07·CVSS 4.0
CVE-2014-0221 [MEDIUM] CVE-2014-0221 CVE-2014-0198 CVE-2014-0224 CVE-2014-0195 CVE-2010-5298 CVE-2014-3470 mingw-openssl: various flaws [epel-7]
CVE-2014-0221 CVE-2014-0198 CVE-2014-0224 CVE-2014-0195 CVE-2010-5298 CVE-2014-3470 mingw-openssl: various flaws [epel-7]
The unfixed package from Fedora was added to EPEL-7.
+++ This bug was initially created as a clone of Bug #1096234 +++
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relev
Bugzilla
CVE-2014-0221 CVE-2014-0198 CVE-2014-0224 CVE-2014-0195 CVE-2010-5298 CVE-2014-3470 openssl: various flaws [fedora-all]
bugzilla·2014-05-09·CVSS 4.0
CVE-2014-0221 [MEDIUM] CVE-2014-0221 CVE-2014-0198 CVE-2014-0224 CVE-2014-0195 CVE-2010-5298 CVE-2014-3470 openssl: various flaws [fedora-all]
CVE-2014-0221 CVE-2014-0198 CVE-2014-0224 CVE-2014-0195 CVE-2010-5298 CVE-2014-3470 openssl: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when avai
Bugzilla
CVE-2014-0221 CVE-2014-0198 CVE-2014-0224 CVE-2014-0195 CVE-2010-5298 CVE-2014-3470 mingw-openssl: various flaws [fedora-all]
bugzilla·2014-05-09·CVSS 4.0
CVE-2014-0221 [MEDIUM] CVE-2014-0221 CVE-2014-0198 CVE-2014-0224 CVE-2014-0195 CVE-2010-5298 CVE-2014-3470 mingw-openssl: various flaws [fedora-all]
CVE-2014-0221 CVE-2014-0198 CVE-2014-0224 CVE-2014-0195 CVE-2010-5298 CVE-2014-3470 mingw-openssl: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field whe
Bugzilla
CVE-2014-0198 openssl: SSL_MODE_RELEASE_BUFFERS NULL pointer dereference in do_ssl3_write()
bugzilla·2014-05-02·CVSS 4.3
CVE-2014-0198 [MEDIUM] CVE-2014-0198 openssl: SSL_MODE_RELEASE_BUFFERS NULL pointer dereference in do_ssl3_write()
CVE-2014-0198 openssl: SSL_MODE_RELEASE_BUFFERS NULL pointer dereference in do_ssl3_write()
The OpenBSD Project reports:
An attacker can trigger generation of an SSL alert which could cause a null pointer dereference.
External references:
http://ftp.openbsd.org/pub/OpenBSD/patches/5.5/common/005_openssl.patch.sig
https://rt.openssl.org/Ticket/Display.html?user=guest&pass=guest&id=3321
Discussion:
This issue can happen when SSL_MODE_RELEASE_BUFFERS mode is enabled. Support for SSL_MODE_RELEASE_BUFFERS was only introduced upstream in OpenSSL version 1.0.0, so this does not affect openssl packages in Red Hat Enterprise Linux 5 and earlier.
https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=8671b89
In Red Hat Enterprise Linux 6, the only package that enabled SSL_MODE_RELEASE_B
Tenable
OpenSSL ChangeCipherSpec Dashboard
blogs_tenable·2014-06-06
OpenSSL ChangeCipherSpec Dashboard
by Steve Tilson June 6, 2014
The OpenSSL ChangeCipherSpec vulnerability is a Man-in-the-Middle attack that can allow an attacker modify the traffic between two hosts during a phase of an SSL/TLS handshake. This flaw could allow a MiTM attacker to decrypt or forge SSL messages by telling the service to begin encrypted communications before key material has been exchanged, which causes predictable keys to be used to secure future traffic. This dashboard identifies systems vulnerable to the OpenSSL ChangeCipherSpec vulnerability.
Man-in-the-Middle (MitM) vulnerabilities allow an attacker to insert themselves into a communication channel. While each of the endpoints assume they are communicating directly with each other, all the traffic is in fact flowing through the attacker. This type of h
http://advisories.mageia.org/MGASA-2014-0204.htmlhttp://aix.software.ibm.com/aix/efixes/security/openssl_advisory9.aschttp://kb.juniper.net/InfoCenter/index?page=content&id=JSA10629http://kb.juniper.net/InfoCenter/index?page=content&id=KB29195http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136470.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-August/136473.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00016.htmlhttp://lists.opensuse.org/opensuse-updates/2014-05/msg00036.htmlhttp://lists.opensuse.org/opensuse-updates/2014-05/msg00037.htmlhttp://marc.info/?l=bugtraq&m=140389274407904&w=2http://marc.info/?l=bugtraq&m=140389355508263&w=2http://marc.info/?l=bugtraq&m=140431828824371&w=2http://marc.info/?l=bugtraq&m=140448122410568&w=2http://marc.info/?l=bugtraq&m=140544599631400&w=2http://marc.info/?l=bugtraq&m=140621259019789&w=2http://marc.info/?l=bugtraq&m=140752315422991&w=2http://marc.info/?l=bugtraq&m=140904544427729&w=2http://marc.info/?l=bugtraq&m=141658880509699&w=2http://puppetlabs.com/security/cve/cve-2014-0198http://seclists.org/fulldisclosure/2014/Dec/23http://secunia.com/advisories/58337http://secunia.com/advisories/58667http://secunia.com/advisories/58713http://secunia.com/advisories/58714http://secunia.com/advisories/58939http://secunia.com/advisories/58945http://secunia.com/advisories/58977http://secunia.com/advisories/59126http://secunia.com/advisories/59162http://secunia.com/advisories/59163http://secunia.com/advisories/59190http://secunia.com/advisories/59202http://secunia.com/advisories/59264http://secunia.com/advisories/59282http://secunia.com/advisories/59284http://secunia.com/advisories/59287http://secunia.com/advisories/59300http://secunia.com/advisories/59301http://secunia.com/advisories/59306http://secunia.com/advisories/59310http://secunia.com/advisories/59342http://secunia.com/advisories/59374http://secunia.com/advisories/59398http://secunia.com/advisories/59413http://secunia.com/advisories/59437http://secunia.com/advisories/59438http://secunia.com/advisories/59440http://secunia.com/advisories/59449http://secunia.com/advisories/59450http://secunia.com/advisories/59490http://secunia.com/advisories/59491http://secunia.com/advisories/59514http://secunia.com/advisories/59525http://secunia.com/advisories/59529http://secunia.com/advisories/59655http://secunia.com/advisories/59666http://secunia.com/advisories/59669http://secunia.com/advisories/59721http://secunia.com/advisories/59784http://secunia.com/advisories/59990http://secunia.com/advisories/60049http://secunia.com/advisories/60066http://secunia.com/advisories/60571http://secunia.com/advisories/61254http://security.gentoo.org/glsa/glsa-201407-05.xmlhttp://support.citrix.com/article/CTX140876http://support.f5.com/kb/en-us/solutions/public/15000/300/sol15329.htmlhttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140605-opensslhttp://www-01.ibm.com/support/docview.wss?uid=nas8N1020163http://www-01.ibm.com/support/docview.wss?uid=swg21673137http://www-01.ibm.com/support/docview.wss?uid=swg21676035http://www-01.ibm.com/support/docview.wss?uid=swg21676062http://www-01.ibm.com/support/docview.wss?uid=swg21676419http://www-01.ibm.com/support/docview.wss?uid=swg21676529http://www-01.ibm.com/support/docview.wss?uid=swg21676655http://www-01.ibm.com/support/docview.wss?uid=swg21676879http://www-01.ibm.com/support/docview.wss?uid=swg21676889http://www-01.ibm.com/support/docview.wss?uid=swg21677527http://www-01.ibm.com/support/docview.wss?uid=swg21677695http://www-01.ibm.com/support/docview.wss?uid=swg21677828http://www-01.ibm.com/support/docview.wss?uid=swg21677836http://www-01.ibm.com/support/docview.wss?uid=swg21678167http://www-01.ibm.com/support/docview.wss?uid=swg21683332http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095754http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095755http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095756http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095757http://www.blackberry.com/btsc/KB36051http://www.debian.org/security/2014/dsa-2931http://www.fortiguard.com/advisory/FG-IR-14-018/http://www.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-345106.htmhttp://www.ibm.com/support/docview.wss?uid=swg21676356http://www.ibm.com/support/docview.wss?uid=swg24037783http://www.mandriva.com/security/advisories?name=MDVSA-2014:080http://www.mandriva.com/security/advisories?name=MDVSA-2015:062http://www.openbsd.org/errata55.html#005_opensslhttp://www.openssl.org/news/secadv_20140605.txthttp://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.htmlhttp://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html
+ 124 more references
2014-05-06
Published