cbcvebase.
CVE-2014-0221
published 2014-06-05

CVE-2014-0221: The dtls1_get_message_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h allows remote attackers to cause a…

PriorityP337medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
87.89%
99.7th percentile
The dtls1_get_message_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h allows remote attackers to cause a denial of service (recursion and client crash) via a DTLS hello message in an invalid DTLS handshake.

Affected

24 ranges
VendorProductVersion rangeFixed in
ciscoproducts
debianopenssl< openssl 1.0.1h-1 (bookworm)openssl 1.0.1h-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
mariadbmariadb>= 10.0.0 < 10.0.1310.0.13
opensslopenssl>= 0 < 1.0.1h-11.0.1h-1
opensslopenssl>= 0 < 1.0.1h-11.0.1h-1
opensslopenssl>= 0 < 1.0.1h-11.0.1h-1
opensslopenssl>= 0 < 1.0.1h-11.0.1h-1
opensslopenssl>= 0 < 1.0.1f-1ubuntu2.31.0.1f-1ubuntu2.3
opensslopenssl>= 0 < 1.0.1f-1ubuntu2.41.0.1f-1ubuntu2.4
opensslopenssl>= 0 < 1.0.1f-1ubuntu2.21.0.1f-1ubuntu2.2
opensslopenssl>= 0.9.8 < 0.9.8za0.9.8za
opensslopenssl>= 1.0.0 < 1.0.0m1.0.0m
opensslopenssl>= 1.0.1 < 1.0.1h1.0.1h
opensuseleap
opensuseopensuse
redhatenterprise_linux
redhatenterprise_linux
redhatstorage
suselinux_enterprise_desktop
suselinux_enterprise_server
suselinux_enterprise_software_development_kit
suselinux_enterprise_workstation_extension

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability is triggered by a DTLS hello message sent within an invalid DTLS handshake, causing recursion in dtls1_get_message_fragment() in d1_both.c, resulting in a client crash (DoS). Detect anomalous/malformed DTLS ClientHello or ServerHello handshake packets targeting DTLS clients.
  • The attack vector specifically targets DTLS clients using OpenSSL — detection should focus on DTLS handshake traffic where a specially crafted ServerHello triggers recursive processing.
  • Only devices acting as SSL/DTLS clients or servers terminating DTLS connections are affected; devices merely passing through DTLS traffic are not. Focus monitoring on DTLS endpoints, not transit devices.
  • ·Affected OpenSSL versions are: before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h. Systems running these versions and acting as DTLS clients are vulnerable.

CVSS provenance

nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv6.8MEDIUM
vendor_cisco10.0CRITICAL
vendor_ubuntu6.8MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.