Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-0224

Опубликовано: 05 июн. 2014
Источник: ubuntu
Приоритет: medium
CVSS2: 5.8
CVSS3: 7.4

Описание

OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive information, via a crafted TLS handshake, aka the "CCS Injection" vulnerability.

РелизСтатусПримечание
devel

released

1.0.1f-1ubuntu4
esm-infra-legacy/trusty

released

1.0.1f-1ubuntu2.2
lucid

released

0.9.8k-7ubuntu8.18
precise

released

1.0.1-4ubuntu5.14
saucy

released

1.0.1e-3ubuntu1.4
trusty

released

1.0.1f-1ubuntu2.2
trusty/esm

released

1.0.1f-1ubuntu2.2
upstream

released

0.9.8za,1.0.1h

Показывать по

РелизСтатусПримечание
devel

released

0.9.8o-7ubuntu4
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [0.9.8o-7ubuntu3.2.14.04.1]]
lucid

DNE

precise

released

0.9.8o-7ubuntu3.2
saucy

released

0.9.8o-7ubuntu3.2.13.10.1
trusty

released

0.9.8o-7ubuntu3.2.14.04.1
trusty/esm

DNE

trusty was released [0.9.8o-7ubuntu3.2.14.04.1]
upstream

released

0.9.8za

Показывать по

5.8 Medium

CVSS2

7.4 High

CVSS3

Связанные уязвимости

redhat
больше 11 лет назад

OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive information, via a crafted TLS handshake, aka the "CCS Injection" vulnerability.

CVSS3: 7.4
nvd
больше 11 лет назад

OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive information, via a crafted TLS handshake, aka the "CCS Injection" vulnerability.

CVSS3: 7.4
debian
больше 11 лет назад

OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h d ...

CVSS3: 7.4
github
больше 3 лет назад

OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive information, via a crafted TLS handshake, aka the "CCS Injection" vulnerability.

oracle-oval
больше 11 лет назад

ELSA-2014-0680: openssl098e security update (IMPORTANT)

5.8 Medium

CVSS2

7.4 High

CVSS3