CVE Vulnerabilities

CVE-2014-3566

Published: Oct 15, 2014 | Modified: Apr 12, 2025
CVSS 3.x
3.4
LOW
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
5 IMPORTANT
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the POODLE issue.

Affected Software

NameVendorStart VersionEnd Version
Enterprise_linuxRedhat5 (including)5 (including)
Enterprise_linux_desktopRedhat6.0 (including)6.0 (including)
Enterprise_linux_desktopRedhat7.0 (including)7.0 (including)
Enterprise_linux_desktop_supplementaryRedhat5.0 (including)5.0 (including)
Enterprise_linux_desktop_supplementaryRedhat6.0 (including)6.0 (including)
Enterprise_linux_serverRedhat6.0 (including)6.0 (including)
Enterprise_linux_serverRedhat7.0 (including)7.0 (including)
Enterprise_linux_server_supplementaryRedhat5.0 (including)5.0 (including)
Enterprise_linux_server_supplementaryRedhat6.0 (including)6.0 (including)
Enterprise_linux_server_supplementaryRedhat7.0 (including)7.0 (including)
Enterprise_linux_workstationRedhat6.0 (including)6.0 (including)
Enterprise_linux_workstationRedhat7.0 (including)7.0 (including)
Enterprise_linux_workstation_supplementaryRedhat6.0 (including)6.0 (including)
Enterprise_linux_workstation_supplementaryRedhat7.0 (including)7.0 (including)
Oracle Java for Red Hat Enterprise Linux 5RedHatjava-1.7.0-oracle-1:1.7.0.75-1jpp.1.el5_11*
Oracle Java for Red Hat Enterprise Linux 5RedHatjava-1.6.0-sun-1:1.6.0.91-1jpp.1.el5_11*
Oracle Java for Red Hat Enterprise Linux 6RedHatjava-1.7.0-oracle-1:1.7.0.75-1jpp.1.el6*
Oracle Java for Red Hat Enterprise Linux 6RedHatjava-1.8.0-oracle-1:1.8.0.31-1jpp.1.el6*
Oracle Java for Red Hat Enterprise Linux 6RedHatjava-1.6.0-sun-1:1.6.0.91-1jpp.1.el6*
Oracle Java for Red Hat Enterprise Linux 7RedHatjava-1.7.0-oracle-1:1.7.0.75-1jpp.2.el7*
Oracle Java for Red Hat Enterprise Linux 7RedHatjava-1.6.0-sun-1:1.6.0.91-1jpp.1.el7*
Red Hat Enterprise Linux 5RedHatjava-1.7.0-openjdk-1:1.7.0.75-2.5.4.0.el5_11*
Red Hat Enterprise Linux 5RedHatjava-1.6.0-openjdk-1:1.6.0.34-1.13.6.1.el5_11*
Red Hat Enterprise Linux 5 SupplementaryRedHatjava-1.7.0-ibm-1:1.7.0.8.0-1jpp.1.el5*
Red Hat Enterprise Linux 5 SupplementaryRedHatjava-1.6.0-ibm-1:1.6.0.16.2-1jpp.1.el5*
Red Hat Enterprise Linux 5 SupplementaryRedHatjava-1.5.0-ibm-1:1.5.0.16.8-1jpp.1.el5*
Red Hat Enterprise Linux 6RedHatjava-1.7.0-openjdk-1:1.7.0.75-2.5.4.0.el6_6*
Red Hat Enterprise Linux 6RedHatjava-1.8.0-openjdk-1:1.8.0.31-1.b13.el6_6*
Red Hat Enterprise Linux 6RedHatjava-1.6.0-openjdk-1:1.6.0.34-1.13.6.1.el6_6*
Red Hat Enterprise Linux 7RedHatnspr-0:4.10.6-3.el7*
Red Hat Enterprise Linux 7RedHatnss-0:3.16.2.3-5.el7*
Red Hat Enterprise Linux 7RedHatnss-softokn-0:3.16.2.3-9.el7*
Red Hat Enterprise Linux 7RedHatnss-util-0:3.16.2.3-2.el7*
Red Hat Enterprise Linux 7RedHatjava-1.7.0-openjdk-1:1.7.0.75-2.5.4.2.el7_0*
Red Hat Enterprise Linux 7RedHatjava-1.6.0-openjdk-1:1.6.0.34-1.13.6.1.el7_0*
Red Hat JBoss Enterprise Application Platform 5.2RedHat*
Red Hat JBoss Enterprise Application Platform 6.3RedHatopenssl*
Red Hat JBoss Web Platform 5.2RedHat*
Red Hat JBoss Web Server 2.1RedHatopenssl*
Red Hat OpenShift Enterprise 2.0RedHatopenshift-origin-node-proxy-0:1.16.4.2-1.el6op*
Red Hat OpenShift Enterprise 2.1RedHatopenshift-origin-node-proxy-0:1.22.3.4-1.el6op*
Red Hat Satellite 5.6RedHatjava-1.6.0-ibm-1:1.6.0.16.3-1jpp.1.el6*
Red Hat Satellite 6.0RedHatcandlepin-0:0.9.23.1-1.el7*
Red Hat Satellite 6.0RedHatforeman-0:1.6.0.49-1.el6sat*
Red Hat Satellite 6.0RedHatkatello-agent-0:1.5.3-6.el6sat*
Red Hat Satellite 6.0RedHatpulp-0:2.4.3-1.el6sat*
Red Hat Satellite 6.0RedHatpulp-nodes-0:2.4.3-0.1.beta.el6sat*
Red Hat Satellite 6.0RedHatpulp-puppet-0:2.4.3-1.el6sat*
Red Hat Satellite 6.0RedHatpulp-rpm-0:2.4.3-1.el6sat*
Red Hat Satellite 6.0RedHatruby193-rubygem-katello-0:1.5.0-93.el7sat*
Red Hat Satellite 6.0RedHatrubygem-apipie-bindings-0:0.0.8-2.el7sat*
Red Hat Satellite 6.0RedHatrubygem-hammer_cli_import-0:0.10.4-1.3.el6sat*
Supplementary for Red Hat Enterprise Linux 6RedHatjava-1.6.0-ibm-1:1.6.0.16.2-1jpp.1.el6_6*
Supplementary for Red Hat Enterprise Linux 6RedHatjava-1.7.1-ibm-1:1.7.1.2.0-1jpp.3.el6_6*
Supplementary for Red Hat Enterprise Linux 6RedHatjava-1.5.0-ibm-1:1.5.0.16.8-1jpp.1.el6_6*
Supplementary for Red Hat Enterprise Linux 6RedHatjava-1.7.0-ibm-1:1.7.0.8.0-1jpp.1.el6_6*
Supplementary for Red Hat Enterprise Linux 7RedHatjava-1.7.1-ibm-1:1.7.1.2.0-1jpp.3.el7_0*
NssUbuntuupstream*
Openjdk-6Ubuntulucid*
Openjdk-6Ubuntuprecise*
Openjdk-6Ubuntutrusty*
Openjdk-6Ubuntuupstream*
Openjdk-6Ubuntuutopic*
Openjdk-7Ubuntuprecise*
Openjdk-7Ubuntutrusty*
Openjdk-7Ubuntuupstream*
Openjdk-7Ubuntuutopic*
OpensslUbuntuartful*
OpensslUbuntubionic*
OpensslUbuntucosmic*
OpensslUbuntudevel*
OpensslUbuntudisco*
OpensslUbuntuesm-infra-legacy/trusty*
OpensslUbuntuesm-infra/bionic*
OpensslUbuntuesm-infra/focal*
OpensslUbuntuesm-infra/xenial*
OpensslUbuntufips-preview/jammy*
OpensslUbuntufips-updates/jammy*
OpensslUbuntufocal*
OpensslUbuntujammy*
OpensslUbuntukinetic*
OpensslUbuntulucid*
OpensslUbuntulunar*
OpensslUbuntumantic*
OpensslUbuntunoble*
OpensslUbuntuoracular*
OpensslUbuntuplucky*
OpensslUbuntuprecise*
OpensslUbuntuquesting*
OpensslUbuntutrusty*
OpensslUbuntutrusty/esm*
OpensslUbuntuutopic*
OpensslUbuntuvivid*
OpensslUbuntuvivid/stable-phone-overlay*
OpensslUbuntuvivid/ubuntu-core*
OpensslUbuntuwily*
OpensslUbuntuxenial*
OpensslUbuntuyakkety*
OpensslUbuntuzesty*
Openssl098Ubuntuprecise*
Openssl098Ubuntutrusty*
Openssl098Ubuntuutopic*
Openssl098Ubuntuvivid*
PoundUbuntuesm-infra-legacy/trusty*
PoundUbuntuoracular*
PoundUbuntuplucky*
PoundUbuntuprecise*
PoundUbuntutrusty*
PoundUbuntutrusty/esm*
PoundUbuntuutopic*
PoundUbuntuvivid*

References