CVE-2014-3470

Severity
4.3MEDIUM
EPSS
91.4%
top 0.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 5
Latest updateMay 14

Description

The ssl3_send_client_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h, when an anonymous ECDH cipher suite is used, allows remote attackers to cause a denial of service (NULL pointer dereference and client crash) by triggering a NULL certificate value.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages10 packages

NVDopenssl/openssl1.0.01.0.0m+2
Debianopenssl< 1.0.1h-1+3
NVDmariadb/mariadb10.0.010.0.13
NVDopensuse/leap42.1

Also affects: Fedora 19, 20, Enterprise Linux 5, 6.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-rq9h-37gr-2m9p: The ssl3_send_client_key_exchange function in s3_clnt2022-05-14
OSV
CVE-2014-3470: The ssl3_send_client_key_exchange function in s3_clnt2014-06-05
CVEList
CVE-2014-3470: The ssl3_send_client_key_exchange function in s3_clnt2014-06-05

📋Vendor Advisories

5
Ubuntu
OpenSSL vulnerabilities2014-06-05
Cisco
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products2014-06-05
Red Hat
openssl: client-side denial of service when using anonymous ECDH2014-06-05
BSD
FreeBSD-SA-14:14.openssl: OpenSSL multiple vulnerabilities2014-06-05
Debian
CVE-2014-3470: openssl - The ssl3_send_client_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8z...2014

💬Community

5
Bugzilla
CVE-2014-0221 CVE-2014-0198 CVE-2014-0224 CVE-2014-0195 CVE-2010-5298 CVE-2014-3470 mingw-openssl: various flaws [epel-7]2014-08-07
Bugzilla
CVE-2014-3470 CVE-2014-0221 CVE-2014-0224 CVE-2014-0195 mingw32-openssl: various flaws [epel-5]2014-08-07
Bugzilla
CVE-2014-3470 openssl: client-side denial of service when using anonymous ECDH2014-06-02
Bugzilla
CVE-2014-0221 CVE-2014-0198 CVE-2014-0224 CVE-2014-0195 CVE-2010-5298 CVE-2014-3470 openssl: various flaws [fedora-all]2014-05-09
Bugzilla
CVE-2014-0221 CVE-2014-0198 CVE-2014-0224 CVE-2014-0195 CVE-2010-5298 CVE-2014-3470 mingw-openssl: various flaws [fedora-all]2014-05-09