CVE-2014-0224

OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, … (CVE-2014-0224)

Description

OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive information, via a crafted TLS handshake, aka the "CCS Injection" vulnerability.

Source: CVELISTV5NVD

Metrics

Severity
high
no public PoC known
7.4
Source: nvd-v3
99.9 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
95.3 %
High — model estimates ≥ 50% chance of real-world exploitation within 30 days.
Published
2014-06-05 21:00 UTC

Affected operating systems

  • linux

    redhat / enterprise_linux4

  • linux

    redhat / enterprise_linux5

  • linux

    redhat / enterprise_linux6.0

  • os

    siemens / application_processing_engine_firmware

  • os

    siemens / cp1543-1_firmware

  • os

    fedoraproject / fedora19

  • os

    fedoraproject / fedora20

  • os

    opensuse / opensuse13.1

  • os

    opensuse / opensuse13.2

  • os

    siemens / rox_firmware

  • os

    siemens / s7-1500_firmware

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • filezilla-project

    filezilla_server0.9.45

  • mariadb

    mariadb10.0.0 – 10.0.13

  • nodejs

    node.js0.10.29

  • openssl

    openssl1.0.0 – 1.0.0m

  • openssl

    openssl1.0.1 – 1.0.1h

  • openssl

    openssl0.9.8za

  • python

    python2.7.0 – 2.7.8

  • python

    python3.4.0 – 3.4.2

  • redhat

    jboss_enterprise_application_platform

  • redhat

    jboss_enterprise_web_platform

  • redhat

    jboss_enterprise_web_server

  • redhat

    storage

References & sources

IDCVE-2014-0224