Input validation error in OpenSSL - CVE-2014-3511

 

Input validation error in OpenSSL - CVE-2014-3511

Published: August 14, 2014 / Updated: August 10, 2020


Vulnerability identifier: #VU41413
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-3511
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to manipulate data.

The ssl23_get_client_hello function in s23_srvr.c in OpenSSL 1.0.1 before 1.0.1i allows man-in-the-middle attackers to force the use of TLS 1.0 by triggering ClientHello message fragmentation in communication between a client and server that both support later TLS versions, related to a "protocol downgrade" issue.


Affected software

OpenSSL
Gentoo Linux
Amazon Linux AMI
Fedora
Slackware Linux
HP Insight Control
HP System Management Homepage
WMI Mapper
FlashSystem V840 9846-AE1 & 9848-AE1
FlashSystem 840 9840-AE1 & 9843-AE1
TMS RAMSAN 710 & 810 Machine Type 9833 -AS1 & -AE1
FlashSystem 710 & 810 Machine Type 9830 -AS1 & -AE1
IBM FlashSystem 720 and 820 Machine Type 9831 –AS2 and -AE2
TMS RAMSAN 720 and 820 machine type 9834 -AS2 & AE2
FlashSystem V840 9846-AC0 & -AC1 and 9848-AC0 & -AC1
mingw-openssl
SAN Volume Controller and Storwize Family
IBM Storwize V7000
IBM Storwize V3500
IBM Storwize V5000
IBM Storwize V3700
HPE Service Manager

How to mitigate CVE-2014-3511

Install update from vendor's website.

mingw-openssl - addressed in versions 1.0.1j-1.el7, 1.0.1j-1.fc21
FlashSystem V840 9846-AE1 & 9848-AE1 - update to 1.1.2.7
FlashSystem 840 9840-AE1 & 9843-AE1 - update to 1.1.2.7
TMS RAMSAN 710 & 810 Machine Type 9833 -AS1 & -AE1 - update to 5.6.2
FlashSystem 710 & 810 Machine Type 9830 -AS1 & -AE1 - update to 5.6.2
IBM FlashSystem 720 and 820 Machine Type 9831 –AS2 and -AE2 - update to 6.3.2
TMS RAMSAN 720 and 820 machine type 9834 -AS2 & AE2 - update to 6.3.2
SAN Volume Controller and Storwize Family - addressed in versions 7.2.0.9, 7.3.0.7, 7.4.0.0
IBM Storwize V7000 - update to 7.2.0.9
IBM Storwize V3500 - addressed in versions 7.2.0.9, 7.3.0.7, 7.4.0.0
IBM Storwize V5000 - addressed in versions 7.2.0.9, 7.3.0.7, 7.4.0.0
IBM Storwize V3700 - addressed in versions 7.2.0.9, 7.3.0.7, 7.4.0.0
FlashSystem V840 9846-AC0 & -AC1 and 9848-AC0 & -AC1 - update to 7.3.0.7
HPE Service Manager - addressed in versions 7.11.720 p22, 9.21.706 P9, 9.34.2003 p2

External References

Related Security Bulletins