The dtls1_get_message_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h allows remote attackers to cause a denial of service (recursion and client crash) via a DTLS hello message in an invalid DTLS handshake.

Project Subscriptions

Vendors Products
Fedoraproject Subscribe
Mariadb Subscribe
Mariadb Subscribe
Openssl Subscribe
Openssl Subscribe
Opensuse Subscribe
Enterprise Linux Subscribe
Jboss Enterprise Application Platform Subscribe
Jboss Enterprise Web Server Subscribe
Storage Subscribe
Linux Enterprise Desktop Subscribe
Linux Enterprise Server Subscribe
Linux Enterprise Software Development Kit Subscribe
Linux Enterprise Workstation Extension Subscribe
Advisories
Source ID Title
Debian DSA Debian DSA DSA-2950-1 openssl security update
Debian DSA Debian DSA DSA-2950-2 openssl update
Ubuntu USN Ubuntu USN USN-2232-1 OpenSSL vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
http://aix.software.ibm.com/aix/efixes/security/openssl_advisory9.asc cve-icon cve-icon
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10629 cve-icon cve-icon
http://linux.oracle.com/errata/ELSA-2014-1053.html cve-icon cve-icon
http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136470.html cve-icon cve-icon
http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136473.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00016.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.html cve-icon cve-icon
http://marc.info/?l=bugtraq&m=140266410314613&w=2 cve-icon cve-icon
http://marc.info/?l=bugtraq&m=140317760000786&w=2 cve-icon cve-icon
http://marc.info/?l=bugtraq&m=140389274407904&w=2 cve-icon cve-icon
http://marc.info/?l=bugtraq&m=140389355508263&w=2 cve-icon cve-icon
http://marc.info/?l=bugtraq&m=140431828824371&w=2 cve-icon cve-icon
http://marc.info/?l=bugtraq&m=140448122410568&w=2 cve-icon cve-icon
http://marc.info/?l=bugtraq&m=140482916501310&w=2 cve-icon cve-icon
http://marc.info/?l=bugtraq&m=140491231331543&w=2 cve-icon cve-icon
http://marc.info/?l=bugtraq&m=140499827729550&w=2 cve-icon cve-icon
http://marc.info/?l=bugtraq&m=140621259019789&w=2 cve-icon cve-icon
http://marc.info/?l=bugtraq&m=140752315422991&w=2 cve-icon cve-icon
http://marc.info/?l=bugtraq&m=140904544427729&w=2 cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2014-1021.html cve-icon cve-icon
http://seclists.org/fulldisclosure/2014/Dec/23 cve-icon cve-icon
http://secunia.com/advisories/58337 cve-icon cve-icon
http://secunia.com/advisories/58615 cve-icon cve-icon
http://secunia.com/advisories/58713 cve-icon cve-icon
http://secunia.com/advisories/58714 cve-icon cve-icon
http://secunia.com/advisories/58939 cve-icon cve-icon
http://secunia.com/advisories/58945 cve-icon cve-icon
http://secunia.com/advisories/58977 cve-icon cve-icon
http://secunia.com/advisories/59027 cve-icon cve-icon
http://secunia.com/advisories/59120 cve-icon cve-icon
http://secunia.com/advisories/59126 cve-icon cve-icon
http://secunia.com/advisories/59162 cve-icon cve-icon
http://secunia.com/advisories/59167 cve-icon cve-icon
http://secunia.com/advisories/59175 cve-icon cve-icon
http://secunia.com/advisories/59189 cve-icon cve-icon
http://secunia.com/advisories/59192 cve-icon cve-icon
http://secunia.com/advisories/59221 cve-icon cve-icon
http://secunia.com/advisories/59284 cve-icon cve-icon
http://secunia.com/advisories/59287 cve-icon cve-icon
http://secunia.com/advisories/59300 cve-icon cve-icon
http://secunia.com/advisories/59301 cve-icon cve-icon
http://secunia.com/advisories/59306 cve-icon cve-icon
http://secunia.com/advisories/59310 cve-icon cve-icon
http://secunia.com/advisories/59342 cve-icon cve-icon
http://secunia.com/advisories/59364 cve-icon cve-icon
http://secunia.com/advisories/59365 cve-icon cve-icon
http://secunia.com/advisories/59413 cve-icon cve-icon
http://secunia.com/advisories/59429 cve-icon cve-icon
http://secunia.com/advisories/59437 cve-icon cve-icon
http://secunia.com/advisories/59441 cve-icon cve-icon
http://secunia.com/advisories/59449 cve-icon cve-icon
http://secunia.com/advisories/59450 cve-icon cve-icon
http://secunia.com/advisories/59451 cve-icon cve-icon
http://secunia.com/advisories/59454 cve-icon cve-icon
http://secunia.com/advisories/59460 cve-icon cve-icon
http://secunia.com/advisories/59490 cve-icon cve-icon
http://secunia.com/advisories/59491 cve-icon cve-icon
http://secunia.com/advisories/59495 cve-icon cve-icon
http://secunia.com/advisories/59514 cve-icon cve-icon
http://secunia.com/advisories/59518 cve-icon cve-icon
http://secunia.com/advisories/59528 cve-icon cve-icon
http://secunia.com/advisories/59655 cve-icon cve-icon
http://secunia.com/advisories/59659 cve-icon cve-icon
http://secunia.com/advisories/59666 cve-icon cve-icon
http://secunia.com/advisories/59669 cve-icon cve-icon
http://secunia.com/advisories/59721 cve-icon cve-icon
http://secunia.com/advisories/59784 cve-icon cve-icon
http://secunia.com/advisories/59895 cve-icon cve-icon
http://secunia.com/advisories/59990 cve-icon cve-icon
http://secunia.com/advisories/60571 cve-icon cve-icon
http://secunia.com/advisories/60687 cve-icon cve-icon
http://secunia.com/advisories/61254 cve-icon cve-icon
http://security.gentoo.org/glsa/glsa-201407-05.xml cve-icon cve-icon
http://support.apple.com/kb/HT6443 cve-icon cve-icon
http://support.citrix.com/article/CTX140876 cve-icon cve-icon
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140605-openssl cve-icon cve-icon
http://www-01.ibm.com/support/docview.wss?uid=isg400001841 cve-icon cve-icon
http://www-01.ibm.com/support/docview.wss?uid=isg400001843 cve-icon cve-icon
http://www-01.ibm.com/support/docview.wss?uid=nas8N1020163 cve-icon cve-icon
http://www-01.ibm.com/support/docview.wss?uid=swg21673137 cve-icon cve-icon
http://www-01.ibm.com/support/docview.wss?uid=swg21675821 cve-icon cve-icon
http://www-01.ibm.com/support/docview.wss?uid=swg21676035 cve-icon cve-icon
http://www-01.ibm.com/support/docview.wss?uid=swg21676062 cve-icon cve-icon
http://www-01.ibm.com/support/docview.wss?uid=swg21676071 cve-icon cve-icon
http://www-01.ibm.com/support/docview.wss?uid=swg21676419 cve-icon cve-icon
http://www-01.ibm.com/support/docview.wss?uid=swg21676879 cve-icon cve-icon
http://www-01.ibm.com/support/docview.wss?uid=swg21676889 cve-icon cve-icon
http://www-01.ibm.com/support/docview.wss?uid=swg21677527 cve-icon cve-icon
http://www-01.ibm.com/support/docview.wss?uid=swg21677695 cve-icon cve-icon
http://www-01.ibm.com/support/docview.wss?uid=swg21677828 cve-icon cve-icon
http://www-01.ibm.com/support/docview.wss?uid=swg21678167 cve-icon cve-icon
http://www-01.ibm.com/support/docview.wss?uid=swg21678289 cve-icon cve-icon
http://www-01.ibm.com/support/docview.wss?uid=swg21683332 cve-icon cve-icon
http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095754 cve-icon cve-icon
http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095755 cve-icon cve-icon
http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095756 cve-icon cve-icon
http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095757 cve-icon cve-icon
http://www.blackberry.com/btsc/KB36051 cve-icon cve-icon
http://www.fortiguard.com/advisory/FG-IR-14-018/ cve-icon cve-icon
http://www.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-345106.htm cve-icon cve-icon
http://www.ibm.com/support/docview.wss?uid=swg21676226 cve-icon cve-icon
http://www.ibm.com/support/docview.wss?uid=swg21676356 cve-icon cve-icon
http://www.ibm.com/support/docview.wss?uid=swg21676793 cve-icon cve-icon
http://www.ibm.com/support/docview.wss?uid=swg24037783 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDVSA-2014:105 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDVSA-2014:106 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDVSA-2015:062 cve-icon cve-icon
http://www.novell.com/support/kb/doc.php?id=7015264 cve-icon cve-icon
http://www.novell.com/support/kb/doc.php?id=7015300 cve-icon cve-icon
http://www.openssl.org/news/secadv_20140605.txt cve-icon cve-icon
http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html cve-icon cve-icon
http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html cve-icon cve-icon
http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html cve-icon cve-icon
http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html cve-icon cve-icon
http://www.securityfocus.com/archive/1/534161/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/bid/67901 cve-icon cve-icon
http://www.securitytracker.com/id/1030337 cve-icon cve-icon
http://www.vmware.com/security/advisories/VMSA-2014-0006.html cve-icon cve-icon
http://www.vmware.com/security/advisories/VMSA-2014-0012.html cve-icon cve-icon
http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=6060&myns=phmc&mync=E cve-icon cve-icon
http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=6061&myns=phmc&mync=E cve-icon cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=1103593 cve-icon cve-icon
https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commit%3Bh=d3152655d5319ce883c8e3ac4b99f8de4c59d846 cve-icon cve-icon
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05301946 cve-icon cve-icon
https://kb.bluecoat.com/index?page=content&id=SA80 cve-icon cve-icon
https://kc.mcafee.com/corporate/index?page=content&id=SB10075 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2014-0221 cve-icon
https://www.cve.org/CVERecord?id=CVE-2014-0221 cve-icon
https://www.novell.com/support/kb/doc.php?id=7015271 cve-icon cve-icon
https://www.openssl.org/news/secadv_20140605.txt cve-icon
History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-06T09:05:39.372Z

Reserved: 2013-12-03T00:00:00

Link: CVE-2014-0221

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2014-06-05T21:55:06.207

Modified: 2025-04-12T10:46:40.837

Link: CVE-2014-0221

cve-icon Redhat

Severity : Moderate

Publid Date: 2014-06-05T00:00:00Z

Links: CVE-2014-0221 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses