Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-0221

Опубликовано: 05 июн. 2014
Источник: ubuntu
Приоритет: medium
EPSS Высокий
CVSS2: 4.3

Описание

The dtls1_get_message_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h allows remote attackers to cause a denial of service (recursion and client crash) via a DTLS hello message in an invalid DTLS handshake.

РелизСтатусПримечание
devel

released

1.0.1f-1ubuntu4
esm-infra-legacy/trusty

not-affected

1.0.1f-1ubuntu2.2
lucid

released

0.9.8k-7ubuntu8.18
precise

released

1.0.1-4ubuntu5.14
saucy

released

1.0.1e-3ubuntu1.4
trusty

released

1.0.1f-1ubuntu2.2
trusty/esm

not-affected

1.0.1f-1ubuntu2.2
upstream

released

1.0.1h

Показывать по

РелизСтатусПримечание
devel

released

0.9.8o-7ubuntu4
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [0.9.8o-7ubuntu3.2.14.04.1]]
lucid

DNE

precise

released

0.9.8o-7ubuntu3.2
saucy

released

0.9.8o-7ubuntu3.2.13.10.1
trusty

released

0.9.8o-7ubuntu3.2.14.04.1
trusty/esm

DNE

trusty was released [0.9.8o-7ubuntu3.2.14.04.1]
upstream

released

0.9.8za

Показывать по

EPSS

Процентиль: 99%
0.82097
Высокий

4.3 Medium

CVSS2

Связанные уязвимости

redhat
около 11 лет назад

The dtls1_get_message_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h allows remote attackers to cause a denial of service (recursion and client crash) via a DTLS hello message in an invalid DTLS handshake.

nvd
около 11 лет назад

The dtls1_get_message_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h allows remote attackers to cause a denial of service (recursion and client crash) via a DTLS hello message in an invalid DTLS handshake.

debian
около 11 лет назад

The dtls1_get_message_fragment function in d1_both.c in OpenSSL before ...

github
около 3 лет назад

The dtls1_get_message_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h allows remote attackers to cause a denial of service (recursion and client crash) via a DTLS hello message in an invalid DTLS handshake.

fstec
больше 10 лет назад

Уязвимость программного обеспечения Cisco Unified Communications Manager, позволяющая злоумышленнику вызвать отказ в обслуживании

EPSS

Процентиль: 99%
0.82097
Высокий

4.3 Medium

CVSS2