CVE-2014-0224
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, … (CVE-2014-0224)
Description
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive information, via a crafted TLS handshake, aka the "CCS Injection" vulnerability.
Metrics
Affected operating systems
linux
redhat / enterprise_linux4
linux
redhat / enterprise_linux5
linux
redhat / enterprise_linux6.0
os
siemens / application_processing_engine_firmware
os
siemens / cp1543-1_firmware
os
fedoraproject / fedora19
os
fedoraproject / fedora20
os
opensuse / opensuse13.1
os
opensuse / opensuse13.2
os
siemens / rox_firmware
os
siemens / s7-1500_firmware
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
filezilla-project
filezilla_server0.9.45
mariadb
mariadb10.0.0 – 10.0.13
nodejs
node.js0.10.29
openssl
openssl1.0.0 – 1.0.0m
openssl
openssl1.0.1 – 1.0.1h
openssl
openssl0.9.8za
python
python2.7.0 – 2.7.8
python
python3.4.0 – 3.4.2
redhat
jboss_enterprise_application_platform
redhat
jboss_enterprise_web_platform
redhat
jboss_enterprise_web_server
redhat
storage
References & sources
- http://secunia.com/advisories/59342third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/59669third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/59525third-party-advisoryx_refsource_SECUNIA
- http://marc.info/?l=bugtraq&m=140604261522465&w=2vendor-advisoryx_refsource_HP
- http://secunia.com/advisories/59004third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/59530third-party-advisoryx_refsource_SECUNIA
- http://www-01.ibm.com/support/docview.wss?uid=swg21675626x_refsource_CONFIRM
- http://secunia.com/advisories/59824third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/59282third-party-advisoryx_refsource_SECUNIA
- http://www.novell.com/support/kb/doc.php?id=7015300x_refsource_CONFIRM
- http://secunia.com/advisories/59215third-party-advisoryx_refsource_SECUNIA
- https://bugzilla.redhat.com/show_bug.cgi?id=1103586x_refsource_CONFIRM
- http://secunia.com/advisories/59990third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/59264third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/59454third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/58492third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/59186third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/59188third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/59126third-party-advisoryx_refsource_SECUNIA
- http://marc.info/?l=bugtraq&m=140672208601650&w=2vendor-advisoryx_refsource_HP