TROYANOSYVIRUS
Back to CVEs

CVE-2014-3566

LOW
3.4

Description

The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.

CVE Details

CVSS v3.1 Score3.4
SeverityLOW
CVSS VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N
Attack VectorNETWORK
ComplexityHIGH
Privileges RequiredNONE
User InteractionREQUIRED
Published10/15/2014
Last Modified4/12/2025
Sourcenvd
Honeypot Sightings0

Affected Products

apple:mac_os_xdebian:debian_linuxfedoraproject:fedoraibm:aixibm:viosmageia:mageianetbsd:netbsdnovell:suse_linux_enterprise_desktopnovell:suse_linux_enterprise_servernovell:suse_linux_enterprise_software_development_kitopenssl:opensslopensuse:opensuseoracle:databaseredhat:enterprise_linuxredhat:enterprise_linux_desktopredhat:enterprise_linux_desktop_supplementaryredhat:enterprise_linux_serverredhat:enterprise_linux_server_supplementaryredhat:enterprise_linux_workstationredhat:enterprise_linux_workstation_supplementary

Weaknesses (CWE)

CWE-310

References

http://advisories.mageia.org/MGASA-2014-0416.html(af854a3a-2127-422b-91ae-364da2661108)
http://blog.nodejs.org/2014/10/23/node-v0-10-33-stable/(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=141450452204552&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=141450973807288&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=141477196830952&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=141576815022399&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=141577087123040&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=141577350823734&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=141620103726640&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=141628688425177&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=141694355519663&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=141697638231025&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=141697676231104&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=141703183219781&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=141715130023061&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=141775427104070&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=141813976718456&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=141814011518700&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=141879378918327&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=142103967620673&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=142118135300698&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=142296755107581&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=142350196615714&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=142350298616097&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=142350743917559&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=142354438527235&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=142357976805598&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=142495837901899&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=142496355704097&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=142546741516006&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=142607790919348&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=142624590206005&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=142624619906067(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=142624619906067&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=142624679706236&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=142624719706349&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=142660345230545&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=142721830231196&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=142721887231400&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=142740155824959&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=142791032306609&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=142804214608580&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=142805027510172&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=142962817202793&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=143039249603103&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=143101048219218&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=143290371927178&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=143290437727362&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=143290522027658&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=143290583027876&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=143558137709884&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=143558192010071&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=143628269912142&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=144101915224472&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=144251162130364&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=144294141001552&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=145983526810210&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=openssl-dev&m=141333049205629&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2014-1652.html(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2014-1653.html(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2014-1692.html(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2014-1876.html(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2014-1877.html(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2014-1880.html(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2014-1881.html(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2014-1882.html(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2014-1920.html(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2014-1948.html(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2015-0068.html(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2015-0079.html(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2015-0080.html(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2015-0085.html(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2015-0086.html(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2015-0264.html(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2015-0698.html(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2015-1545.html(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2015-1546.html(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/59627(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/60056(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/60206(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/60792(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/60859(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/61019(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/61130(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/61303(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/61316(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/61345(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/61359(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/61782(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/61810(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/61819(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/61825(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/61827(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/61926(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/61995(af854a3a-2127-422b-91ae-364da2661108)
http://support.apple.com/HT204244(af854a3a-2127-422b-91ae-364da2661108)
http://support.citrix.com/article/CTX200238(af854a3a-2127-422b-91ae-364da2661108)
http://www-01.ibm.com/support/docview.wss?uid=swg21686997(af854a3a-2127-422b-91ae-364da2661108)
http://www-01.ibm.com/support/docview.wss?uid=swg21687172(af854a3a-2127-422b-91ae-364da2661108)
http://www-01.ibm.com/support/docview.wss?uid=swg21687611(af854a3a-2127-422b-91ae-364da2661108)
http://www-01.ibm.com/support/docview.wss?uid=swg21688283(af854a3a-2127-422b-91ae-364da2661108)
http://www-01.ibm.com/support/docview.wss?uid=swg21692299(af854a3a-2127-422b-91ae-364da2661108)
http://www.debian.org/security/2014/dsa-3053(af854a3a-2127-422b-91ae-364da2661108)
http://www.debian.org/security/2015/dsa-3144(af854a3a-2127-422b-91ae-364da2661108)
http://www.debian.org/security/2015/dsa-3147(af854a3a-2127-422b-91ae-364da2661108)
http://www.debian.org/security/2015/dsa-3253(af854a3a-2127-422b-91ae-364da2661108)
http://www.debian.org/security/2016/dsa-3489(af854a3a-2127-422b-91ae-364da2661108)
http://www.kb.cert.org/vuls/id/577193(af854a3a-2127-422b-91ae-364da2661108)
http://www.securityfocus.com/archive/1/533746(af854a3a-2127-422b-91ae-364da2661108)
http://www.securityfocus.com/archive/1/533747(af854a3a-2127-422b-91ae-364da2661108)
http://www.securityfocus.com/bid/70574(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1031029(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1031039(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1031085(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1031086(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1031087(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1031088(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1031089(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1031090(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1031091(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1031092(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1031093(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1031094(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1031095(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1031096(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1031105(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1031106(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1031107(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1031120(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1031123(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1031124(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1031130(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1031131(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1031132(af854a3a-2127-422b-91ae-364da2661108)
http://www.ubuntu.com/usn/USN-2486-1(af854a3a-2127-422b-91ae-364da2661108)
http://www.ubuntu.com/usn/USN-2487-1(af854a3a-2127-422b-91ae-364da2661108)
http://www.us-cert.gov/ncas/alerts/TA14-290A(af854a3a-2127-422b-91ae-364da2661108)
https://access.redhat.com/articles/1232123(af854a3a-2127-422b-91ae-364da2661108)
https://bto.bluecoat.com/security-advisory/sa83(af854a3a-2127-422b-91ae-364da2661108)
https://bugzilla.mozilla.org/show_bug.cgi?id=1076983(af854a3a-2127-422b-91ae-364da2661108)
https://bugzilla.redhat.com/show_bug.cgi?id=1152789(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/mpgn/poodle-PoC(af854a3a-2127-422b-91ae-364da2661108)
https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02(af854a3a-2127-422b-91ae-364da2661108)
https://security.gentoo.org/glsa/201507-14(af854a3a-2127-422b-91ae-364da2661108)
https://security.gentoo.org/glsa/201606-11(af854a3a-2127-422b-91ae-364da2661108)
https://security.netapp.com/advisory/ntap-20141015-0001/(af854a3a-2127-422b-91ae-364da2661108)
https://support.apple.com/HT205217(af854a3a-2127-422b-91ae-364da2661108)
https://support.apple.com/kb/HT6527(af854a3a-2127-422b-91ae-364da2661108)
https://support.apple.com/kb/HT6529(af854a3a-2127-422b-91ae-364da2661108)
https://support.apple.com/kb/HT6531(af854a3a-2127-422b-91ae-364da2661108)
https://support.apple.com/kb/HT6535(af854a3a-2127-422b-91ae-364da2661108)
https://support.apple.com/kb/HT6536(af854a3a-2127-422b-91ae-364da2661108)
https://support.apple.com/kb/HT6541(af854a3a-2127-422b-91ae-364da2661108)
https://support.apple.com/kb/HT6542(af854a3a-2127-422b-91ae-364da2661108)
https://support.citrix.com/article/CTX216642(af854a3a-2127-422b-91ae-364da2661108)
https://support.lenovo.com/product_security/poodle(af854a3a-2127-422b-91ae-364da2661108)
https://support.lenovo.com/us/en/product_security/poodle(af854a3a-2127-422b-91ae-364da2661108)
https://templatelab.com/ssl-poodle/(af854a3a-2127-422b-91ae-364da2661108)
https://www.elastic.co/blog/logstash-1-4-3-released(af854a3a-2127-422b-91ae-364da2661108)
https://www.imperialviolet.org/2014/10/14/poodle.html(af854a3a-2127-422b-91ae-364da2661108)
https://www.openssl.org/news/secadv_20141015.txt(af854a3a-2127-422b-91ae-364da2661108)
https://www.openssl.org/~bodo/ssl-poodle.pdf(af854a3a-2127-422b-91ae-364da2661108)
https://www.suse.com/support/kb/doc.php?id=7015773(af854a3a-2127-422b-91ae-364da2661108)

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.