Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2014-3569

Overview

Vulnerability Score 5.0 5.0
CVE Id CVE-2014-3569
Last Modified 16 Jul 2015 10:00:17
Published 24 Dec 2014 06:59:00
Confidentiality Impact NONE NONE
Integrity Impact NONE NONE
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2014-3569

Summary

The ssl23_get_client_hello function in s23_srvr.c in OpenSSL 0.9.8zc, 1.0.0o, and 1.0.1j does not properly handle attempts to use unsupported protocols, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an unexpected handshake, as demonstrated by an SSLv3 handshake to a no-ssl3 application with certain error handling. NOTE: this issue became relevant after the CVE-2014-3568 fix.

Vulnerable Systems

Application

  • Openssl 1.0.1j


References

CONFIRM - https://security-tracker.debian.org/tracker/CVE-2014-3569

CONFIRM - https://git.openssl.org/gitweb/?p=openssl.git;a=commit;h=b82924741b4bd590da890619be671f4635e46c2b

CONFIRM - https://git.openssl.org/gitweb/?p=openssl.git;a=commit;h=6ce9687b5aba5391fc0de50e18779eb676d0e04d

CONFIRM - https://git.openssl.org/gitweb/?p=openssl.git;a=commit;h=392fa7a952e97d82eac6958c81ed1e256e6b8ca5

CONFIRM - http://rt.openssl.org/Ticket/Display.html?id=3571&user=guest&pass=guest

CONFIRM - http://people.canonical.com/~ubuntu-security/cve/2014/CVE-2014-3569.html

CONFIRM - https://www.openssl.org/news/secadv_20150108.txt

MANDRIVA - MDVSA-2015:019

BID - 71934

DEBIAN - DSA-3125

HP - SSRT101885

SUSE - openSUSE-SU-2015:0130

CISCO - 20150310 Multiple Vulnerabilities in OpenSSL (January 2015) Affecting Cisco Products

HP - HPSBHF03289

MANDRIVA - MDVSA-2015:062

CONFIRM - https://support.apple.com/HT204659

APPLE - APPLE-SA-2015-04-08-2

CONFIRM - http://www.oracle.com/technetwork/topics/security/cpuapr2015-2365600.html

SUSE - SUSE-SU-2015:0946

CONFIRM - http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html

Related Patches

Apple 2015-004 Security Update for Mac OS X 10.8.5 (HT204659)

Apple 2015-004 Security Update for Mac OS X 10.9.5 (HT204659)

Apple Yosemite 10.10.3 Update (Combo) for Mac OS X (HT204659)

Apple Yosemite 10.10.3 Update for Mac OS X (HT204659)

VMSA-2015-0004 VMware Fusion 6.0.6 for Mac OS X (See Notes) (Rev 3)

VMSA-2016-0001 VMware Fusion 7.1.2 for Mac OS X (See Notes)


Last Updated: 27 May 2016 11:08:20