CVE Vulnerabilities

CVE-2011-0014

Published: Feb 19, 2011 | Modified: Sep 19, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
4 MODERATE
AV:N/AC:H/Au:N/C:P/I:N/A:P
RedHat/V3
Ubuntu

ssl/t1_lib.c in OpenSSL 0.9.8h through 0.9.8q and 1.0.0 through 1.0.0c allows remote attackers to cause a denial of service (crash), and possibly obtain sensitive information in applications that use OpenSSL, via a malformed ClientHello handshake message that triggers an out-of-bounds memory access, aka OCSP stapling vulnerability.

Affected Software

Name Vendor Start Version End Version
Openssl Openssl 0.9.8h 0.9.8h
Openssl Openssl 0.9.8i 0.9.8i
Openssl Openssl 0.9.8j 0.9.8j
Openssl Openssl 0.9.8k 0.9.8k
Openssl Openssl 0.9.8l 0.9.8l
Openssl Openssl 0.9.8m 0.9.8m
Openssl Openssl 0.9.8n 0.9.8n
Openssl Openssl 0.9.8o 0.9.8o
Openssl Openssl 0.9.8p 0.9.8p
Openssl Openssl 0.9.8q 0.9.8q
Red Hat Enterprise Linux 6 RedHat openssl-0:1.0.0-10.el6 *
Openssl Ubuntu lucid *
Openssl Ubuntu maverick *
Openssl Ubuntu upstream *

References