NVD
- Id
- 29112
- Name
- CVE-2014-0198
- Description
- The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, does not properly manage a buffer pointer during certain recursive calls, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors that trigger an alert condition.
- Reject
- CVSS Version
- 2
- CVSS Score
- 4.3
- Severity
- Medium
- CVSS Base Score
- 4.3
- CVSS Impact Subscore
- 2.9
- CVSS Exploit Subscore
- 8.6
- CVSS Vector
- (AV:N/AC:M/Au:N/C:N/I:N/A:P)
- Pub Date
- 2017-01-19
- Published
- 2014-05-06
- Modified Date
- 2017-01-18
- Seq
- 2014-0198
Related NVD References
| Id | NVD Id | NVD No. | Reference | Actions |
|---|---|---|---|---|
| 153997 | 29112 | CVE-2014-0198 | http://advisories.mageia.org/MGASA-2014-0204.html | View |
| 153998 | 29112 | CVE-2014-0198 | http://aix.software.ibm.com/aix/efixes/security/openssl_advisory9.asc | View |
| 153999 | 29112 | CVE-2014-0198 | http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10629 | View |
| 154000 | 29112 | CVE-2014-0198 | http://kb.juniper.net/InfoCenter/index?page=content&id=KB29195 | View |
| 154001 | 29112 | CVE-2014-0198 | FEDORA-2014-9301 | View |
| 154002 | 29112 | CVE-2014-0198 | FEDORA-2014-9308 | View |
| 154003 | 29112 | CVE-2014-0198 | SUSE-SU-2015:0743 | View |
| 154004 | 29112 | CVE-2014-0198 | openSUSE-SU-2014:0634 | View |
| 154005 | 29112 | CVE-2014-0198 | openSUSE-SU-2014:0635 | View |
| 154006 | 29112 | CVE-2014-0198 | HPSBMU03057 | View |
| 154007 | 29112 | CVE-2014-0198 | HPSBMU03056 | View |
| 154008 | 29112 | CVE-2014-0198 | HPSBMU03055 | View |
| 154009 | 29112 | CVE-2014-0198 | HPSBMU03051 | View |
| 154010 | 29112 | CVE-2014-0198 | HPSBGN03068 | View |
| 154011 | 29112 | CVE-2014-0198 | HPSBMU03074 | View |
| 154012 | 29112 | CVE-2014-0198 | HPSBMU03062 | View |
| 154013 | 29112 | CVE-2014-0198 | HPSBMU03076 | View |
| 154014 | 29112 | CVE-2014-0198 | HPSBHF03052 | View |
| 154015 | 29112 | CVE-2014-0198 | http://puppetlabs.com/security/cve/cve-2014-0198 | View |
| 154016 | 29112 | CVE-2014-0198 | 20141205 NEW: VMSA-2014-0012 - VMware vSphere product updates address security vulnerabilities | View |
| 154017 | 29112 | CVE-2014-0198 | 58337 | View |
| 154018 | 29112 | CVE-2014-0198 | 58667 | View |
| 154019 | 29112 | CVE-2014-0198 | 58713 | View |
| 154020 | 29112 | CVE-2014-0198 | 58714 | View |
| 154021 | 29112 | CVE-2014-0198 | 58945 | View |
| 154022 | 29112 | CVE-2014-0198 | 58977 | View |
| 154023 | 29112 | CVE-2014-0198 | 59163 | View |
| 154024 | 29112 | CVE-2014-0198 | 59190 | View |
| 154025 | 29112 | CVE-2014-0198 | 59202 | View |
| 154026 | 29112 | CVE-2014-0198 | 59264 | View |
| 154027 | 29112 | CVE-2014-0198 | 59282 | View |
| 154028 | 29112 | CVE-2014-0198 | 59284 | View |
| 154029 | 29112 | CVE-2014-0198 | 59287 | View |
| 154030 | 29112 | CVE-2014-0198 | 59306 | View |
| 154031 | 29112 | CVE-2014-0198 | 59310 | View |
| 154032 | 29112 | CVE-2014-0198 | 59374 | View |
| 154033 | 29112 | CVE-2014-0198 | 59398 | View |
| 154034 | 29112 | CVE-2014-0198 | 59437 | View |
| 154035 | 29112 | CVE-2014-0198 | 59440 | View |
| 154036 | 29112 | CVE-2014-0198 | 59449 | View |
| 154037 | 29112 | CVE-2014-0198 | 59525 | View |
| 154038 | 29112 | CVE-2014-0198 | 59529 | View |
| 154039 | 29112 | CVE-2014-0198 | 61254 | View |
| 154040 | 29112 | CVE-2014-0198 | GLSA-201407-05 | View |
| 154041 | 29112 | CVE-2014-0198 | http://support.citrix.com/article/CTX140876 | View |
| 154042 | 29112 | CVE-2014-0198 | http://support.f5.com/kb/en-us/solutions/public/15000/300/sol15329.html | View |
| 154043 | 29112 | CVE-2014-0198 | 20140605 Multiple Vulnerabilities in OpenSSL Affecting Cisco Products | View |
| 154044 | 29112 | CVE-2014-0198 | http://www-01.ibm.com/support/docview.wss?uid=nas8N1020163 | View |
| 154045 | 29112 | CVE-2014-0198 | http://www-01.ibm.com/support/docview.wss?uid=swg21673137 | View |
| 154046 | 29112 | CVE-2014-0198 | http://www-01.ibm.com/support/docview.wss?uid=swg21676035 | View |
| 154047 | 29112 | CVE-2014-0198 | http://www-01.ibm.com/support/docview.wss?uid=swg21676062 | View |
| 154048 | 29112 | CVE-2014-0198 | http://www-01.ibm.com/support/docview.wss?uid=swg21676419 | View |
| 154049 | 29112 | CVE-2014-0198 | http://www-01.ibm.com/support/docview.wss?uid=swg21676529 | View |
| 154050 | 29112 | CVE-2014-0198 | http://www-01.ibm.com/support/docview.wss?uid=swg21676655 | View |
| 154051 | 29112 | CVE-2014-0198 | http://www-01.ibm.com/support/docview.wss?uid=swg21676879 | View |
| 154052 | 29112 | CVE-2014-0198 | http://www-01.ibm.com/support/docview.wss?uid=swg21676889 | View |
| 154053 | 29112 | CVE-2014-0198 | http://www-01.ibm.com/support/docview.wss?uid=swg21677527 | View |
| 154054 | 29112 | CVE-2014-0198 | http://www-01.ibm.com/support/docview.wss?uid=swg21677695 | View |
| 154055 | 29112 | CVE-2014-0198 | http://www-01.ibm.com/support/docview.wss?uid=swg21677828 | View |
| 154056 | 29112 | CVE-2014-0198 | http://www-01.ibm.com/support/docview.wss?uid=swg21677836 | View |
| 154057 | 29112 | CVE-2014-0198 | http://www-01.ibm.com/support/docview.wss?uid=swg21678167 | View |
| 154058 | 29112 | CVE-2014-0198 | http://www-01.ibm.com/support/docview.wss?uid=swg21683332 | View |
| 154059 | 29112 | CVE-2014-0198 | http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095754 | View |
| 154060 | 29112 | CVE-2014-0198 | http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095755 | View |
| 154061 | 29112 | CVE-2014-0198 | http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095756 | View |
| 154062 | 29112 | CVE-2014-0198 | http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095757 | View |
| 154063 | 29112 | CVE-2014-0198 | http://www.blackberry.com/btsc/KB36051 | View |
| 154064 | 29112 | CVE-2014-0198 | DSA-2931 | View |
| 154065 | 29112 | CVE-2014-0198 | http://www.fortiguard.com/advisory/FG-IR-14-018/ | View |
| 154066 | 29112 | CVE-2014-0198 | http://www.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-345106.htm | View |
| 154067 | 29112 | CVE-2014-0198 | http://www.ibm.com/support/docview.wss?uid=swg21676356 | View |
| 154068 | 29112 | CVE-2014-0198 | http://www.ibm.com/support/docview.wss?uid=swg24037783 | View |
| 154069 | 29112 | CVE-2014-0198 | MDVSA-2014:080 | View |
| 154070 | 29112 | CVE-2014-0198 | MDVSA-2015:062 | View |
| 154071 | 29112 | CVE-2014-0198 | [5.5] 005: RELIABILITY FIX: May 1, 2014 | View |
| 154072 | 29112 | CVE-2014-0198 | http://www.openssl.org/news/secadv_20140605.txt | View |
| 154073 | 29112 | CVE-2014-0198 | http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html | View |
| 154074 | 29112 | CVE-2014-0198 | http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html | View |
| 154075 | 29112 | CVE-2014-0198 | 20141205 NEW: VMSA-2014-0012 - VMware vSphere product updates address security vulnerabilities | View |
| 154076 | 29112 | CVE-2014-0198 | 67193 | View |
| 154077 | 29112 | CVE-2014-0198 | http://www.vmware.com/security/advisories/VMSA-2014-0006.html | View |
| 154078 | 29112 | CVE-2014-0198 | http://www.vmware.com/security/advisories/VMSA-2014-0012.html | View |
| 154079 | 29112 | CVE-2014-0198 | https://bugzilla.redhat.com/show_bug.cgi?id=1093837 | View |
| 154080 | 29112 | CVE-2014-0198 | https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05301946 | View |
| 154081 | 29112 | CVE-2014-0198 | https://kb.bluecoat.com/index?page=content&id=SA80 | View |
| 154082 | 29112 | CVE-2014-0198 | https://kc.mcafee.com/corporate/index?page=content&id=SB10075 | View |
| 154083 | 29112 | CVE-2014-0198 | https://rt.openssl.org/Ticket/Display.html?user=guest&pass=guest&id=3321 | View |
| 154084 | 29112 | CVE-2014-0198 | https://www.novell.com/support/kb/doc.php?id=7015271 | View |
Related JVN
| Id | Name | Title | Summary | Cveinfo Name | Cveinfo Id | Nvdinfo Name | Nvdinfo Id | Cvssv2 | Cvssv3 | Jvnurl | Published Date | Last Updated Date | Actions |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 13517 | JVNDB-2014-002392 | OpenSSL の s3_pkt.c 内の do_ssl3_write 関数におけるサービス運用妨害 (DoS) の脆弱性 | OpenSSL の s3_pkt.c 内の do_ssl3_write 関数は、SSL_MODE_RELEASE_BUFFERS が有効な場合、特定の再帰呼び出し中にバッファのポインタを適切に管理しないため、サービス運用妨害 (NULL ポインタデリファレンスおよびアプリケーションクラッシュ) 状態にされる脆弱性が存在します。 | CVE-2014-0198 | 67599 | CVE-2014-0198 | 29112 | 4.3 | http://jvndb.jvn.jp/ja/contents/2014/JVNDB-2014-002392.html | 2014-04-21 | 2015-12-17 | View |