Input validation error in OpenSSL - CVE-2014-5139

 

Input validation error in OpenSSL - CVE-2014-5139

Published: August 14, 2014 / Updated: February 16, 2021


Vulnerability identifier: #VU41415
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-5139
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows remote SSL servers to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can cause a denial of service (NULL pointer dereference and client application crash) via a ServerHello message that includes an SRP ciphersuite without the required negotiation of that ciphersuite with the client.


Affected software

OpenSSL
Gentoo Linux
Amazon Linux AMI
Slackware Linux
HP Insight Control
HP System Management Homepage
WMI Mapper
HP Version Control Agent
Version Control Repository Manager
HP Virtual Connect Enterprise Manager
HPE Service Manager

How to mitigate CVE-2014-5139

Install update from vendor's website.

HP Version Control Agent - update to 7.3.4
Version Control Repository Manager - update to 7.4.1
HP Virtual Connect Enterprise Manager - update to 7.4.1
HPE Service Manager - addressed in versions 7.11.720 p22, 9.21.706 P9, 9.34.2003 p2

External References

Related Security Bulletins