Resource management error in OpenSSL - CVE-2014-3470
Published: April 4, 2018
Vulnerability identifier: #VU11536
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-3470
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to an error when processing ECDH ciphersuites in TLS clients. A remote attacker can send a specially crafted response to vulnerable OpenSSL client and cause the application to crash.
The vulnerability exists due to an error when processing ECDH ciphersuites in TLS clients. A remote attacker can send a specially crafted response to vulnerable OpenSSL client and cause the application to crash.
Affected software
OpenSSL
HPE Operations Orchestration
Gentoo Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Fedora
Red Hat Enterprise Linux EUS Compute Node
SUSE Linux
Opensuse
Ubuntu
Slackware Linux
openssl (Ubuntu package)
mingw-openssl
Operations Analytics
TMS RAMSAN 710 & 810 Machine Type 9833 -AS1 & -AE1
FlashSystem 710 & 810 Machine Type 9830 -AS1 & -AE1
TMS RAMSAN 720 and 820 machine type 9834 -AS2 & AE2
IBM FlashSystem 720 and 820 Machine Type 9831 –AS2 and -AE2
IBM BladeCenter Advanced Management Module
HP Smart Update Manager
HPE Operations Orchestration
Gentoo Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Fedora
Red Hat Enterprise Linux EUS Compute Node
SUSE Linux
Opensuse
Ubuntu
Slackware Linux
openssl (Ubuntu package)
mingw-openssl
Operations Analytics
TMS RAMSAN 710 & 810 Machine Type 9833 -AS1 & -AE1
FlashSystem 710 & 810 Machine Type 9830 -AS1 & -AE1
TMS RAMSAN 720 and 820 machine type 9834 -AS2 & AE2
IBM FlashSystem 720 and 820 Machine Type 9831 –AS2 and -AE2
IBM BladeCenter Advanced Management Module
HP Smart Update Manager
How to mitigate CVE-2014-3470
Update to version 0.9.8za, 1.0.0m or 1.0.1h.
openssl (Ubuntu package) - update to 0.9.8k-7ubuntu8.21
mingw-openssl - addressed in versions 1.0.1j-1.el7, 1.0.1j-1.fc21
IBM BladeCenter Advanced Management Module - update to 3.66F
TMS RAMSAN 710 & 810 Machine Type 9833 -AS1 & -AE1 - update to 5.6.2
FlashSystem 710 & 810 Machine Type 9830 -AS1 & -AE1 - update to 5.6.2
TMS RAMSAN 720 and 820 machine type 9834 -AS2 & AE2 - update to 6.3.2
IBM FlashSystem 720 and 820 Machine Type 9831 –AS2 and -AE2 - update to 6.3.2
HP Smart Update Manager - update to 6.4.1
mingw-openssl - addressed in versions 1.0.1j-1.el7, 1.0.1j-1.fc21
IBM BladeCenter Advanced Management Module - update to 3.66F
TMS RAMSAN 710 & 810 Machine Type 9833 -AS1 & -AE1 - update to 5.6.2
FlashSystem 710 & 810 Machine Type 9830 -AS1 & -AE1 - update to 5.6.2
TMS RAMSAN 720 and 820 machine type 9834 -AS2 & AE2 - update to 6.3.2
IBM FlashSystem 720 and 820 Machine Type 9831 –AS2 and -AE2 - update to 6.3.2
HP Smart Update Manager - update to 6.4.1
External References
Related Security Bulletins
- Multiple vulnerabilities in OpenSSL
- Ubuntu update for OpenSSL
- Ubuntu update for OpenSSL
- Ubuntu update for OpenSSL
- Ubuntu update for OpenSSL
- Gentoo update for OpenSSL
- Slackware Linux update for openssl
- SUSE Linux update for OpenSSL
- openSUSE update for openssl
- openSUSE update for openssl
- SUSE Linux update for OpenSSL 1.0
- SUSE Linux update for OpenSSL
- Red Hat update for openssl
- Red Hat update for openssl
- Multiple vulnerabilities in IBM FlashSystem (and TMS RAMSAN) 710, 720, 810, and 820 systems
- Multiple vulnerabilities in HP Software Operation Orchestration
- Multiple vulnerabilities in HP Operations Analytics
- Multiple vulnerabilities in HP Smart Update Manager (HP SUM)
- Multiple vulnerabilities in IBM BladeCenter Advanced Management Module
- Fedora 21 update for mingw-openssl
- Fedora EPEL 7 update for mingw-openssl