CVE Vulnerabilities

CVE-2014-0221

Published: Jun 05, 2014 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

The dtls1_get_message_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h allows remote attackers to cause a denial of service (recursion and client crash) via a DTLS hello message in an invalid DTLS handshake.

Affected Software

Name Vendor Start Version End Version
Openssl Openssl 0.9.8 (including) 0.9.8za (excluding)
Openssl Openssl 1.0.0 (including) 1.0.0m (excluding)
Openssl Openssl 1.0.1 (including) 1.0.1h (excluding)

References