Description
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive information, via a crafted TLS handshake, aka the "CCS Injection" vulnerability.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-2950-1 | openssl security update |
Debian DSA |
DSA-2950-2 | openssl update |
Ubuntu USN |
USN-2232-1 | OpenSSL vulnerabilities |
References
History
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Subscriptions
Fedoraproject
Subscribe
Fedora
Subscribe
Filezilla-project
Subscribe
Filezilla Server
Subscribe
Mariadb
Subscribe
Mariadb
Subscribe
Nodejs
Subscribe
Node.js
Subscribe
Openssl
Subscribe
Openssl
Subscribe
Opensuse
Subscribe
Opensuse
Subscribe
Python
Subscribe
Python
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Jboss Enterprise Application Platform
Subscribe
Jboss Enterprise Web Platform
Subscribe
Jboss Enterprise Web Server
Subscribe
Rhel Els
Subscribe
Rhel Eus
Subscribe
Rhel Mission Critical
Subscribe
Storage
Subscribe
Siemens
Subscribe
Application Processing Engine
Subscribe
Application Processing Engine Firmware
Subscribe
Cp1543-1
Subscribe
Cp1543-1 Firmware
Subscribe
Rox
Subscribe
Rox Firmware
Subscribe
S7-1500
Subscribe
S7-1500 Firmware
Subscribe
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T09:05:39.462Z
Reserved: 2013-12-03T00:00:00.000Z
Link: CVE-2014-0224
No data.
Status : Deferred
Published: 2014-06-05T21:55:07.817
Modified: 2025-04-12T10:46:40.837
Link: CVE-2014-0224
OpenCVE Enrichment
No data.
Debian DSA
Ubuntu USN