4.3

CVE-2014-3470

The ssl3_send_client_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h, when an anonymous ECDH cipher suite is used, allows remote attackers to cause a denial of service (NULL pointer dereference and client crash) by triggering a NULL certificate value.

Data is provided by the National Vulnerability Database (NVD)
OpenSSLOpenSSL Version < 0.9.8za
OpenSSLOpenSSL Version >= 1.0.0 < 1.0.0m
OpenSSLOpenSSL Version >= 1.0.1 < 1.0.1h
RedhatStorage Version2.1
RedhatEnterprise Linux Version5
RedhatEnterprise Linux Version6.0
MariadbMariadb Version >= 10.0.0 < 10.0.13
FedoraprojectFedora Version19
FedoraprojectFedora Version20
OpensuseLeap Version42.1
OpensuseOpensuse Version13.2
SuseLinux Enterprise Desktop Version12 Update-
SuseLinux Enterprise Server Version12 Update-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 91.4% 0.996
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.

http://seclists.org/fulldisclosure/2014/Dec/23
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=140266410314613&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=140317760000786&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=140389274407904&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=140389355508263&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=140448122410568&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=140482916501310&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=140621259019789&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=140752315422991&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=140904544427729&w=2
Third Party Advisory
Mailing List
http://kb.juniper.net/InfoCenter/index?page=content&id=KB29195
Third Party Advisory
Permissions Required
http://marc.info/?l=bugtraq&m=140431828824371&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=140491231331543&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=140499827729550&w=2
Third Party Advisory
Mailing List
http://www.securityfocus.com/bid/67898
Third Party Advisory
VDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=1103600
Patch
Third Party Advisory
Issue Tracking