Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-0224

Опубликовано: 05 июн. 2014
Источник: ubuntu
Приоритет: medium
EPSS Критический
CVSS2: 5.8
CVSS3: 7.4

Описание

OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive information, via a crafted TLS handshake, aka the "CCS Injection" vulnerability.

РелизСтатусПримечание
devel

released

1.0.1f-1ubuntu4
esm-infra-legacy/trusty

not-affected

1.0.1f-1ubuntu2.2
lucid

released

0.9.8k-7ubuntu8.18
precise

released

1.0.1-4ubuntu5.14
saucy

released

1.0.1e-3ubuntu1.4
trusty

released

1.0.1f-1ubuntu2.2
trusty/esm

not-affected

1.0.1f-1ubuntu2.2
upstream

released

0.9.8za,1.0.1h

Показывать по

РелизСтатусПримечание
devel

released

0.9.8o-7ubuntu4
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [0.9.8o-7ubuntu3.2.14.04.1]]
lucid

DNE

precise

released

0.9.8o-7ubuntu3.2
saucy

released

0.9.8o-7ubuntu3.2.13.10.1
trusty

released

0.9.8o-7ubuntu3.2.14.04.1
trusty/esm

DNE

trusty was released [0.9.8o-7ubuntu3.2.14.04.1]
upstream

released

0.9.8za

Показывать по

EPSS

Процентиль: 100%
0.92879
Критический

5.8 Medium

CVSS2

7.4 High

CVSS3

Связанные уязвимости

redhat
около 11 лет назад

OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive information, via a crafted TLS handshake, aka the "CCS Injection" vulnerability.

CVSS3: 7.4
nvd
около 11 лет назад

OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive information, via a crafted TLS handshake, aka the "CCS Injection" vulnerability.

CVSS3: 7.4
debian
около 11 лет назад

OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h d ...

CVSS3: 7.4
github
около 3 лет назад

OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive information, via a crafted TLS handshake, aka the "CCS Injection" vulnerability.

oracle-oval
почти 11 лет назад

ELSA-2014-0680: openssl098e security update (IMPORTANT)

EPSS

Процентиль: 100%
0.92879
Критический

5.8 Medium

CVSS2

7.4 High

CVSS3