CVE-2014-3567
Vulnerability Summary
Timeline
Description
Memory leak in the tls_decrypt_ticket function in t1_lib.c in OpenSSL before 0.9.8zc, 1.0.0 before 1.0.0o, and 1.0.1 before 1.0.1j allows remote attackers to cause a denial of service (memory consumption) via a crafted session ticket that triggers an integrity-check failure.
CVSS Metrics
- v2.0•HIGH•Score: 7.1AV:N/AC:M/Au:N/C:N/I:N/A:C
EPSS Trends
Current EPSS score: 24.27%• Percentile: 96%
Techniques & Countermeasures
- CWE-20•Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
- CWE-399•Resource Management Errors
Weaknesses in this category are related to improper management of system resources.
Affected Systems
- Unknown•OpenSSL
≤ 0.9.8zb | 1.0.0 | 1.0.0:beta1 | 1.0.0:beta2 | 1.0.0:beta3 | 1.0.0:beta4 | 1.0.0:beta5 | 1.0.0a | 1.0.0b | 1.0.0c | 1.0.0d | 1.0.0e | 1.0.0f | 1.0.0g | 1.0.0h | 1.0.0i | 1.0.0j | 1.0.0k | 1.0.0l | 1.0.0m | 1.0.0n | 1.0.1 | 1.0.1:beta1 | 1.0.1:beta2 | 1.0.1:beta3 | 1.0.1a | 1.0.1b | 1.0.1c | 1.0.1d | 1.0.1e | 1.0.1f | 1.0.1g | 1.0.1h | 1.0.1i
References (56)
- http://marc.info/?l=bugtraq&m=142103967620673&w=2
- http://aix.software.ibm.com/aix/efixes/security/openssl_advisory11.asc
- http://marc.info/?l=bugtraq&m=142804214608580&w=2
- http://lists.opensuse.org/opensuse-security-announce/2014-10/msg00008.html
- http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html
- http://marc.info/?l=bugtraq&m=141477196830952&w=2
- http://secunia.com/advisories/61130
- https://www.openssl.org/news/secadv_20141015.txt
- http://www.securitytracker.com/id/1031052
- http://secunia.com/advisories/62070
- http://www.securityfocus.com/bid/70586
- http://secunia.com/advisories/61073
- http://www.ubuntu.com/usn/USN-2385-1
- http://marc.info/?l=bugtraq&m=142791032306609&w=2
- http://security.gentoo.org/glsa/glsa-201412-39.xml
- http://www.debian.org/security/2014/dsa-3053
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05150888
- http://marc.info/?l=bugtraq&m=143290583027876&w=2
- http://marc.info/?l=bugtraq&m=142118135300698&w=2
- http://marc.info/?l=bugtraq&m=142495837901899&w=2
- https://support.apple.com/HT205217
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.html
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commit%3Bh=7fd4ce6a997be5f5c9e744ac527725c2850de203
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05158380
- http://lists.apple.com/archives/security-announce/2015/Sep/msg00002.html
- http://lists.opensuse.org/opensuse-security-announce/2014-11/msg00001.html
- https://kc.mcafee.com/corporate/index?page=content&id=SB10091
- ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2014-015.txt.asc
- http://www.splunk.com/view/SP-CAAANST
- http://secunia.com/advisories/61837
- http://support.apple.com/HT204244
- http://secunia.com/advisories/61207
- http://rhn.redhat.com/errata/RHSA-2014-1652.html
- http://secunia.com/advisories/62124
- http://secunia.com/advisories/59627
- http://secunia.com/advisories/61298
- http://marc.info/?l=bugtraq&m=143290437727362&w=2
- http://lists.opensuse.org/opensuse-security-announce/2014-11/msg00003.html
- http://marc.info/?l=bugtraq&m=142834685803386&w=2
- http://secunia.com/advisories/61990
- http://secunia.com/advisories/61959
- https://blogs.oracle.com/sunsecurity/entry/multiple_vulnerabilities_in_openssl6
- http://advisories.mageia.org/MGASA-2014-0416.html
- http://marc.info/?l=bugtraq&m=142624590206005&w=2
- http://marc.info/?l=bugtraq&m=143290522027658&w=2
- http://rhn.redhat.com/errata/RHSA-2015-0126.html
- http://secunia.com/advisories/61058
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:062
- http://www.mandriva.com/security/advisories?name=MDVSA-2014:203
- http://secunia.com/advisories/62030
- https://support.citrix.com/article/CTX216642
- http://lists.apple.com/archives/security-announce/2015/Jan/msg00003.html
- http://secunia.com/advisories/61819
- http://www-01.ibm.com/support/docview.wss?uid=swg21686997
- http://rhn.redhat.com/errata/RHSA-2014-1692.html