CVE Vulnerabilities

CVE-2014-0224

Inadequate Encryption Strength

Published: Jun 05, 2014 | Modified: Apr 12, 2025
CVSS 3.x
7.4
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
5.8 IMPORTANT
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive information, via a crafted TLS handshake, aka the CCS Injection vulnerability.

Weakness

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

Affected Software

NameVendorStart VersionEnd Version
OpensslOpenssl*0.9.8za (excluding)
OpensslOpenssl1.0.0 (including)1.0.0m (excluding)
OpensslOpenssl1.0.1 (including)1.0.1h (excluding)
Red Hat Enterprise Linux 4 Extended Lifecycle SupportRedHatopenssl-0:0.9.7a-43.22.el4*
Red Hat Enterprise Linux 5RedHatopenssl-0:0.9.8e-27.el5_10.3*
Red Hat Enterprise Linux 5RedHatopenssl097a-0:0.9.7a-12.el5_10.1*
Red Hat Enterprise Linux 5.6 Long LifeRedHatopenssl-0:0.9.8e-12.el5_6.12*
Red Hat Enterprise Linux 5.9 Extended Update SupportRedHatopenssl-0:0.9.8e-26.el5_9.4*
Red Hat Enterprise Linux 6RedHatopenssl-0:1.0.1e-16.el6_5.14*
Red Hat Enterprise Linux 6RedHatopenssl098e-0:0.9.8e-18.el6_5.2*
Red Hat Enterprise Linux 6.2 Advanced Update SupportRedHatopenssl-0:1.0.0-20.el6_2.7*
Red Hat Enterprise Linux 6.3 EUS - Server and Compute Node OnlyRedHatopenssl-0:1.0.0-25.el6_3.3*
Red Hat Enterprise Linux 6.4 Extended Update SupportRedHatopenssl-0:1.0.0-27.el6_4.4*
Red Hat Enterprise Linux 7RedHatopenssl-1:1.0.1e-34.el7_0.3*
Red Hat Enterprise Linux 7RedHatopenssl098e-0:0.9.8e-29.el7_0.2*
Red Hat JBoss Enterprise Application Platform 5.2RedHat*
Red Hat JBoss Enterprise Application Platform 6.2RedHat*
Red Hat JBoss Web Platform 5.2RedHat*
Red Hat JBoss Web Server 2.0RedHatopenssl*
Red Hat Storage 2.1RedHatopenssl-0:1.0.1e-16.el6_5.14*
RHEV 3.X Hypervisor and Agents for RHEL-6RedHatrhev-hypervisor6-0:6.5-20140603.1.el6ev*
OpensslUbuntudevel*
OpensslUbuntuesm-infra-legacy/trusty*
OpensslUbuntulucid*
OpensslUbuntuprecise*
OpensslUbuntusaucy*
OpensslUbuntutrusty*
OpensslUbuntutrusty/esm*
OpensslUbuntuupstream*
Openssl098Ubuntudevel*
Openssl098Ubuntuprecise*
Openssl098Ubuntusaucy*
Openssl098Ubuntutrusty*
Openssl098Ubuntuupstream*

Potential Mitigations

References