CVE-2014-3513Improper Input Validation in Openssl

Severity
7.1HIGHNVD
EPSS
25.7%
top 3.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 19
Latest updateNov 7

Description

Memory leak in d1_srtp.c in the DTLS SRTP extension in OpenSSL 1.0.1 before 1.0.1j allows remote attackers to cause a denial of service (memory consumption) via a crafted handshake message.

CVSS vector

AV:N/AC:M/C:N/I:N/A:CExploitability: 8.6 | Impact: 6.9

Affected Packages11 packages

debiandebian/openssl< openssl 1.0.1j-1 (bookworm)
Debianopenssl/openssl< 1.0.1j-1+3
Ubuntuopenssl/openssl< 1.0.1f-1ubuntu2.7
NVDopenssl/openssl10 versions+9
Appleapple/xcode7.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-mxph-x9r8-xwgr: Memory leak in d1_srtp2022-05-17
OSV
CVE-2014-3513: Memory leak in d1_srtp2014-10-19
OSV
openssl vulnerabilities2014-10-16

📋Vendor Advisories

7
Palo Alto
PAN-SA-2024-0014 Informational Bulletin: Impact of OSS CVEs in Cortex XDR Agent2024-11-07
VMware
VMware vCenter Server, ESXi, Workstation, Player, and Fusion updates address security issues2015-01-27
BSD
FreeBSD-SA-14:23.openssl: OpenSSL multiple vulnerabilities2014-10-21
Ubuntu
OpenSSL vulnerabilities2014-10-16
Red Hat
openssl: SRTP memory leak causes crash when using specially-crafted handshake message2014-10-15

🕵️Threat Intelligence

1
Tenable
[R7] OpenSSL &#039;20141015&#039; Advisory Affects Tenable Products2014-11-07

📄Research Papers

1
arXiv
Server-side verification of client behavior in cryptographic protocols2016-03-13

💬Community

1
Bugzilla
CVE-2014-3513 openssl: SRTP memory leak causes crash when using specially-crafted handshake message2014-10-15