Information disclosure in OpenSSL - CVE-2014-3508

 

Information disclosure in OpenSSL - CVE-2014-3508

Published: August 14, 2014 / Updated: August 10, 2020


Vulnerability identifier: #VU41410
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-3508
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

The OBJ_obj2txt function in crypto/objects/obj_dat.c in OpenSSL 0.9.8 before 0.9.8zb, 1.0.0 before 1.0.0n, and 1.0.1 before 1.0.1i, when pretty printing is used, does not ensure the presence of '' characters, which allows context-dependent attackers to obtain sensitive information from process stack memory by reading output from X509_name_oneline, X509_name_print_ex, and unspecified other functions.


Affected software

OpenSSL
HP-UX
IceWall MCRP
HP Insight Control
HP System Management Homepage
WMI Mapper
IceWall SSO Dfw
HPE IceWall SSO Agent Option
FlashSystem V840 9846-AE1 & 9848-AE1
FlashSystem 840 9840-AE1 & 9843-AE1
SSL for OpenVMS
TMS RAMSAN 710 & 810 Machine Type 9833 -AS1 & -AE1
FlashSystem 710 & 810 Machine Type 9830 -AS1 & -AE1
IBM FlashSystem 720 and 820 Machine Type 9831 –AS2 and -AE2
TMS RAMSAN 720 and 820 machine type 9834 -AS2 & AE2
FlashSystem V840 9846-AC0 & -AC1 and 9848-AC0 & -AC1
Amazon Linux AMI
Fedora
Slackware Linux
mingw-openssl
IBM Storwize V7000
IBM Storwize V5000
IBM Storwize V3700
IBM Storwize V3500
SAN Volume Controller and Storwize Family

How to mitigate CVE-2014-3508

Install update from vendor's website.

mingw-openssl - addressed in versions 1.0.1j-1.el7, 1.0.1j-1.fc21
FlashSystem V840 9846-AE1 & 9848-AE1 - update to 1.1.2.7
FlashSystem 840 9840-AE1 & 9843-AE1 - update to 1.1.2.7
SSL for OpenVMS - update to 1.4-493
TMS RAMSAN 710 & 810 Machine Type 9833 -AS1 & -AE1 - update to 5.6.2
FlashSystem 710 & 810 Machine Type 9830 -AS1 & -AE1 - update to 5.6.2
IBM FlashSystem 720 and 820 Machine Type 9831 –AS2 and -AE2 - update to 6.3.2
TMS RAMSAN 720 and 820 machine type 9834 -AS2 & AE2 - update to 6.3.2
IBM Storwize V7000 - update to 7.2.0.9
IBM Storwize V5000 - addressed in versions 7.2.0.9, 7.3.0.7, 7.4.0.0
SAN Volume Controller and Storwize Family - addressed in versions 7.2.0.9, 7.3.0.7, 7.4.0.0
IBM Storwize V3700 - addressed in versions 7.2.0.9, 7.3.0.7, 7.4.0.0
IBM Storwize V3500 - addressed in versions 7.2.0.9, 7.3.0.7, 7.4.0.0
FlashSystem V840 9846-AC0 & -AC1 and 9848-AC0 & -AC1 - update to 7.3.0.7

External References

Related Security Bulletins