CVE Vulnerabilities

CVE-2011-0014

Published: Feb 19, 2011 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
4 MODERATE
AV:N/AC:H/Au:N/C:P/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

ssl/t1_lib.c in OpenSSL 0.9.8h through 0.9.8q and 1.0.0 through 1.0.0c allows remote attackers to cause a denial of service (crash), and possibly obtain sensitive information in applications that use OpenSSL, via a malformed ClientHello handshake message that triggers an out-of-bounds memory access, aka OCSP stapling vulnerability.

Affected Software

NameVendorStart VersionEnd Version
OpensslOpenssl0.9.8h (including)0.9.8h (including)
OpensslOpenssl0.9.8i (including)0.9.8i (including)
OpensslOpenssl0.9.8j (including)0.9.8j (including)
OpensslOpenssl0.9.8k (including)0.9.8k (including)
OpensslOpenssl0.9.8l (including)0.9.8l (including)
OpensslOpenssl0.9.8m (including)0.9.8m (including)
OpensslOpenssl0.9.8n (including)0.9.8n (including)
OpensslOpenssl0.9.8o (including)0.9.8o (including)
OpensslOpenssl0.9.8p (including)0.9.8p (including)
OpensslOpenssl0.9.8q (including)0.9.8q (including)
Red Hat Enterprise Linux 6RedHatopenssl-0:1.0.0-10.el6*
OpensslUbuntulucid*
OpensslUbuntumaverick*
OpensslUbuntuupstream*

References