Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-0198

Опубликовано: 06 мая 2014
Источник: ubuntu
Приоритет: medium
CVSS2: 4.3

Описание

The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, does not properly manage a buffer pointer during certain recursive calls, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors that trigger an alert condition.

РелизСтатусПримечание
devel

released

1.0.1f-1ubuntu3
esm-infra-legacy/trusty

not-affected

1.0.1f-1ubuntu2.1
lucid

not-affected

code not present
precise

released

1.0.1-4ubuntu5.13
quantal

released

1.0.1c-3ubuntu2.8
saucy

released

1.0.1e-3ubuntu1.3
trusty

released

1.0.1f-1ubuntu2.1
trusty/esm

not-affected

1.0.1f-1ubuntu2.1
upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

not-affected

code not present
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was not-affected [code not present]]
lucid

DNE

precise

not-affected

code not present
quantal

not-affected

code not present
saucy

not-affected

code not present
trusty

not-affected

code not present
trusty/esm

DNE

trusty was not-affected [code not present]
upstream

needs-triage

Показывать по

4.3 Medium

CVSS2

Связанные уязвимости

redhat
больше 11 лет назад

The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, does not properly manage a buffer pointer during certain recursive calls, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors that trigger an alert condition.

nvd
больше 11 лет назад

The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, does not properly manage a buffer pointer during certain recursive calls, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors that trigger an alert condition.

debian
больше 11 лет назад

The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, ...

github
около 3 лет назад

The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, does not properly manage a buffer pointer during certain recursive calls, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors that trigger an alert condition.

oracle-oval
около 11 лет назад

ELSA-2014-0679: openssl security update (IMPORTANT)

4.3 Medium

CVSS2