Information disclosure in OpenSSL - CVE-2014-0160

 

Information disclosure in OpenSSL - CVE-2014-0160

Published: January 25, 2017 / Updated: May 4, 2022


Vulnerability identifier: #VU5373
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-0160
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.

The weakness exists due to an error in the TLS/DTLS heartbeat functionality. A remote attacker can read system memory contents without needing to log on to the server and retrieve private keys, passwords or other sensitive information

Successful exploitation of the vulnerability results in information disclosure on the vulnerable system.

Note: the vulnerability was being actively exploited.



Affected software

OpenSSL
Debian Linux
Gentoo Linux
Amazon Linux AMI
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Opensuse
Slackware Linux
UCMDB Configuration Manager
UCMDB Browser
TippingPoint Next Generation Firewall
Virtual Connect Support Utility (VCSU)
Data ONTAP SMI-S Agent
Insight Management VCEM Web Client SDK (VCEMSDK)
CloudSystem Foundation
Connect-IT
Server Automation
Network Interactive Voice Response (NIVR)
Multimedia Service Environment (MSE)
3PAR OS
HP Insight Control
HP Version Control Agent
XIV Gen3
BladeSystem c-Class Virtual Connect Firmware
HP Onboard Administrator
HPE Service Manager
Red Hat Virtualization
Autonomy WorkSite Server
openssl-solibs
openssl
dev-libs/openssl
HP Smart Update Manager
HP Systems Insight Manager
Version Control Repository Manager
HP AssetManager
IBM Storwize V3700
IBM Storwize V7000
IBM Storwize V5000
IBM Storwize V3500

How to mitigate CVE-2014-0160

Update to version 1.0.1g or later.

TippingPoint Next Generation Firewall - update to 1.1.0.4150
Virtual Connect Support Utility (VCSU) - update to 1.9.1
Data ONTAP SMI-S Agent - update to 5.1P1
BladeSystem c-Class Virtual Connect Firmware - addressed in versions 4.10B, 4.20B
HP Onboard Administrator - addressed in versions 4.12, 4.21
CloudSystem Foundation - update to 8.02
HPE Service Manager - update to 9.33.3000 p3
openssl-solibs - update to 1.0.1g
openssl - update to 1.0.1g
dev-libs/openssl - update to 1.0.1g
Network Interactive Voice Response (NIVR) - addressed in versions 2.0.7 Reactive Patch 004, 2.1.0 Reactive Patch 004
Multimedia Service Environment (MSE) - update to 2.1.2
3PAR OS - addressed in versions 3.1.2 MU1, 3.1.2 MU2, 3.1.2 MU3, 3.1.3 P01
HP Smart Update Manager - update to 6.3.1
IBM Storwize V3700 - addressed in versions 6.4.1.9, 7.1.0.9, 7.2.0.5
IBM Storwize V7000 - addressed in versions 6.4.1.9, 7.1.0.9, 7.2.0.5
IBM Storwize V5000 - addressed in versions 6.4.1.9, 7.1.0.9, 7.2.0.5
IBM Storwize V3500 - addressed in versions 6.4.1.9, 7.1.0.9, 7.2.0.5
HP Systems Insight Manager - addressed in versions 7.2.3, 7.3.2
HP Insight Control - update to 7.3.1
Version Control Repository Manager - update to 7.3.2
HP Version Control Agent - update to 7.3.2
HP AssetManager - update to 9.40.10535 p3
XIV Gen3 - addressed in versions 11.3.1.b, 11.4.1.b

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins