Buffer overflow in OpenSSL - CVE-2014-8176
Published: June 12, 2015 / Updated: August 9, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
The dtls1_clear_queues function in ssl/d1_lib.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h frees data structures without considering that application data can arrive between a ChangeCipherSpec message and a Finished message, which allows remote DTLS peers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unexpected application data.
Affected software
Gentoo Linux
Fedora
Integrated Management Module II (IMM2)
SnapDrive for Unix
SnapDrive for Windows
openssl
dev-libs/openssl
How to mitigate CVE-2014-8176
openssl - addressed in versions 1.0.1k-10.fc21, 1.0.1k-10.fc22
dev-libs/openssl - update to 1.0.1o
SnapDrive for Unix - update to 5.3
SnapDrive for Windows - update to 7.1.4
External References
- http://fortiguard.com/advisory/openssl-vulnerabilities-june-2015
- http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2015-008.txt.asc
- http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00007.html
- http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00037.html
- http://rhn.redhat.com/errata/RHSA-2015-1115.html
- http://rhn.redhat.com/errata/RHSA-2016-2957.html
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150612-openssl
- http://www.debian.org/security/2015/dsa-3287
- http://www.fortiguard.com/advisory/openssl-vulnerabilities-june-2015
- http://www.securityfocus.com/bid/75159
- http://www.securitytracker.com/id/1032564
- http://www.ubuntu.com/usn/USN-2639-1
- https://bto.bluecoat.com/security-advisory/sa98
- https://github.com/openssl/openssl/commit/470990fee0182566d439ef7e82d1abf18b7085d7
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05184351
- https://kc.mcafee.com/corporate/index?page=content&id=SB10122
- https://openssl.org/news/secadv/20150611.txt
- https://rt.openssl.org/Ticket/Display.html?id=3286&user=guest&pass=guest
- https://security.gentoo.org/glsa/201506-02
- https://www.openssl.org/news/secadv_20150611.txt