CVE Vulnerabilities

CVE-2013-6449

Published: Dec 23, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
5 IMPORTANT
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The ssl_get_algorithm2 function in ssl/s3_lib.c in OpenSSL before 1.0.2 obtains a certain version number from an incorrect data structure, which allows remote attackers to cause a denial of service (daemon crash) via crafted traffic from a TLS 1.2 client.

Affected Software

NameVendorStart VersionEnd Version
OpensslOpenssl*1.0.1e (including)
OpensslOpenssl1.0.0 (including)1.0.0 (including)
OpensslOpenssl1.0.0-beta1 (including)1.0.0-beta1 (including)
OpensslOpenssl1.0.0-beta2 (including)1.0.0-beta2 (including)
OpensslOpenssl1.0.0-beta3 (including)1.0.0-beta3 (including)
OpensslOpenssl1.0.0-beta4 (including)1.0.0-beta4 (including)
OpensslOpenssl1.0.0-beta5 (including)1.0.0-beta5 (including)
OpensslOpenssl1.0.0a (including)1.0.0a (including)
OpensslOpenssl1.0.0b (including)1.0.0b (including)
OpensslOpenssl1.0.0c (including)1.0.0c (including)
OpensslOpenssl1.0.0d (including)1.0.0d (including)
OpensslOpenssl1.0.0e (including)1.0.0e (including)
OpensslOpenssl1.0.0f (including)1.0.0f (including)
OpensslOpenssl1.0.0g (including)1.0.0g (including)
OpensslOpenssl1.0.0h (including)1.0.0h (including)
OpensslOpenssl1.0.0i (including)1.0.0i (including)
OpensslOpenssl1.0.0j (including)1.0.0j (including)
OpensslOpenssl1.0.1 (including)1.0.1 (including)
OpensslOpenssl1.0.1-beta1 (including)1.0.1-beta1 (including)
OpensslOpenssl1.0.1-beta2 (including)1.0.1-beta2 (including)
OpensslOpenssl1.0.1-beta3 (including)1.0.1-beta3 (including)
OpensslOpenssl1.0.1a (including)1.0.1a (including)
OpensslOpenssl1.0.1b (including)1.0.1b (including)
OpensslOpenssl1.0.1c (including)1.0.1c (including)
OpensslOpenssl1.0.1d (including)1.0.1d (including)
Red Hat Enterprise Linux 6RedHatopenssl-0:1.0.1e-16.el6_5.4*
RHEV 3.X Hypervisor and Agents for RHEL-6RedHatrhev-hypervisor6-0:6.5-20140112.0.el6ev*
OpensslUbuntuprecise*
OpensslUbuntuquantal*
OpensslUbunturaring*
OpensslUbuntusaucy*

References