CVE-2014-3568NULL Pointer Dereference in Openssl

Severity
5.0MEDIUMNVD
NVD4.3OSV4.3
EPSS
3.5%
top 12.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 19
Latest updateMay 17

Description

OpenSSL before 0.9.8zc, 1.0.0 before 1.0.0o, and 1.0.1 before 1.0.1j does not properly enforce the no-ssl3 build option, which allows remote attackers to bypass intended access restrictions via an SSL 3.0 handshake, related to s23_clnt.c and s23_srvr.c.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages10 packages

debiandebian/openssl< openssl 1.0.1k-1 (bookworm)+1
Debianopenssl/openssl< 1.0.1j-1+7
NVDopenssl/openssl0.9.8zb+26
Appleapple/xcode7.0

🔴Vulnerability Details

4
GHSA
GHSA-66cr-qxrv-fpg2: The ssl23_get_client_hello function in s23_srvr2022-05-17
GHSA
GHSA-3873-898q-6f32: OpenSSL before 02022-05-17
OSV
CVE-2014-3569: The ssl23_get_client_hello function in s23_srvr2014-12-24
OSV
CVE-2014-3568: OpenSSL before 02014-10-19

📋Vendor Advisories

8
VMware
VMware vCenter Server, ESXi, Workstation, Player, and Fusion updates address security issues2015-01-27
BSD
FreeBSD-SA-14:23.openssl: OpenSSL multiple vulnerabilities2014-10-21
Red Hat
openssl: denial of service in ssl23_get_client_hello function2014-10-21
Red Hat
openssl: Build option no-ssl3 is incomplete2014-10-15
Debian
CVE-2014-3569: openssl - The ssl23_get_client_hello function in s23_srvr.c in OpenSSL 0.9.8zc, 1.0.0o, an...2014

🕵️Threat Intelligence

1
Tenable
[R7] OpenSSL &#039;20141015&#039; Advisory Affects Tenable Products2014-11-07

💬Community

2
Bugzilla
CVE-2014-3569 openssl: denial of service in ssl23_get_client_hello function2014-12-25
Bugzilla
CVE-2014-3568 openssl: Build option no-ssl3 is incomplete2014-10-15