cbcvebase.
CVE-2014-0224
published 2014-06-05

CVE-2014-0224: OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows…

high7.4CVSS 3.1
AVNACHPRNUINSUCHIHAN
EXPLOIT
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive information, via a crafted TLS handshake, aka the "CCS Injection" vulnerability.

Affected

35 ranges· showing 25
VendorProductVersion rangeFixed in
ciscoproducts
debianopenssl< openssl 1.0.1h-1 (bookworm)openssl 1.0.1h-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
filezilla-projectfilezilla_server< 0.9.450.9.45
mariadbmariadb>= 10.0.0 < 10.0.1310.0.13
nodejsnode.js< 0.10.290.10.29
opensslopenssl< 0.9.8za0.9.8za
opensslopenssl>= 0 < 1.0.1h-11.0.1h-1
opensslopenssl>= 0 < 1.0.1h-11.0.1h-1
opensslopenssl>= 0 < 1.0.1h-11.0.1h-1
opensslopenssl>= 0 < 1.0.1h-11.0.1h-1
opensslopenssl>= 0 < 1.0.1f-1ubuntu2.31.0.1f-1ubuntu2.3
opensslopenssl>= 0 < 1.0.1f-1ubuntu2.41.0.1f-1ubuntu2.4
opensslopenssl>= 0 < 1.0.1f-1ubuntu2.21.0.1f-1ubuntu2.2
opensslopenssl>= 1.0.0 < 1.0.0m1.0.0m
opensslopenssl>= 1.0.1 < 1.0.1h1.0.1h
opensuseopensuse
opensuseopensuse
paloaltocortex_xdr
paloaltopan-os
pythonpython>= 2.7.0 < 2.7.82.7.8
pythonpython>= 3.4.0 < 3.4.23.4.2
redhatenterprise_linux
redhatenterprise_linux

CVSS provenance

nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
osv7.4HIGH
vulncheck7.4HIGH