Resource management error in OpenSSL - CVE-2014-3506

 

Resource management error in OpenSSL - CVE-2014-3506

Published: August 14, 2014 / Updated: August 10, 2020


Vulnerability identifier: #VU41408
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-3506
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform service disruption.

d1_both.c in the DTLS implementation in OpenSSL 0.9.8 before 0.9.8zb, 1.0.0 before 1.0.0n, and 1.0.1 before 1.0.1i allows remote attackers to cause a denial of service (memory consumption) via crafted DTLS handshake messages that trigger memory allocations corresponding to large length values.


Affected software

OpenSSL
Amazon Linux AMI
Gentoo Linux
Fedora
Slackware Linux
HP Insight Control
HP-UX
FlashSystem V840 9846-AE1 & 9848-AE1
FlashSystem 840 9840-AE1 & 9843-AE1
SSL for OpenVMS
TMS RAMSAN 710 & 810 Machine Type 9833 -AS1 & -AE1
FlashSystem 710 & 810 Machine Type 9830 -AS1 & -AE1
IBM FlashSystem 720 and 820 Machine Type 9831 –AS2 and -AE2
TMS RAMSAN 720 and 820 machine type 9834 -AS2 & AE2
FlashSystem V840 9846-AC0 & -AC1 and 9848-AC0 & -AC1
mingw-openssl
IBM Storwize V7000
IBM Storwize V5000
IBM Storwize V3700
IBM Storwize V3500
SAN Volume Controller and Storwize Family

How to mitigate CVE-2014-3506

Install update from vendor's website.

mingw-openssl - addressed in versions 1.0.1j-1.el7, 1.0.1j-1.fc21
FlashSystem V840 9846-AE1 & 9848-AE1 - update to 1.1.2.7
FlashSystem 840 9840-AE1 & 9843-AE1 - update to 1.1.2.7
SSL for OpenVMS - update to 1.4-493
TMS RAMSAN 710 & 810 Machine Type 9833 -AS1 & -AE1 - update to 5.6.2
FlashSystem 710 & 810 Machine Type 9830 -AS1 & -AE1 - update to 5.6.2
IBM FlashSystem 720 and 820 Machine Type 9831 –AS2 and -AE2 - update to 6.3.2
TMS RAMSAN 720 and 820 machine type 9834 -AS2 & AE2 - update to 6.3.2
IBM Storwize V7000 - update to 7.2.0.9
IBM Storwize V5000 - addressed in versions 7.2.0.9, 7.3.0.7, 7.4.0.0
SAN Volume Controller and Storwize Family - addressed in versions 7.2.0.9, 7.3.0.7, 7.4.0.0
IBM Storwize V3700 - addressed in versions 7.2.0.9, 7.3.0.7, 7.4.0.0
IBM Storwize V3500 - addressed in versions 7.2.0.9, 7.3.0.7, 7.4.0.0
FlashSystem V840 9846-AC0 & -AC1 and 9848-AC0 & -AC1 - update to 7.3.0.7

External References

Related Security Bulletins