CVE-2014-3567 — Improper Input Validation in Openssl
Severity
7.1HIGHNVD
EPSS
21.7%
top 4.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 19
Latest updateNov 7
Description
Memory leak in the tls_decrypt_ticket function in t1_lib.c in OpenSSL before 0.9.8zc, 1.0.0 before 1.0.0o, and 1.0.1 before 1.0.1j allows remote attackers to cause a denial of service (memory consumption) via a crafted session ticket that triggers an integrity-check failure.
CVSS vector
AV:N/AC:M/C:N/I:N/A:CExploitability: 8.6 | Impact: 6.9
Affected Packages12 packages
🔴Vulnerability Details
3📋Vendor Advisories
8Palo Alto
▶
VMware▶
VMware vCenter Server, ESXi, Workstation, Player, and Fusion updates address security issues↗2015-01-27
Red Hat
▶
🕵️Threat Intelligence
1📄Research Papers
1💬Community
1Bugzilla▶
CVE-2014-3567 openssl: Invalid TLS/SSL session tickets could cause memory leak leading to server crash↗2014-10-15