TROYANOSYVIRUS
Voltar para CVEs

CVE-2014-0160

HIGHCISA KEV
7.5

Descricao

The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.

Detalhes CVE

Pontuacao CVSS v3.17.5
SeveridadeHIGH
Vetor CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Vetor de ataqueNETWORK
ComplexidadeLOW
Privilegios necessariosNONE
Interacao do usuarioNONE
Publicado4/7/2014
Ultima modificacao4/21/2026
Fontekev
Avistamentos honeypot0

CISA KEV

FornecedorOpenSSL
ProdutoOpenSSL
Nome da vulnerabilidadeOpenSSL Information Disclosure Vulnerability
Data inclusao KEV2022-05-04
Prazo de remediacao2022-05-25
Uso em ransomwareUnknown

Produtos afetados

broadcom:symantec_messaging_gatewaycanonical:ubuntu_linuxdebian:debian_linuxfedoraproject:fedorafilezilla-project:filezilla_serverintellian:v100intellian:v100_firmwareintellian:v60intellian:v60_firmwaremitel:micollabmitel:mivoiceopenssl:opensslopensuse:opensuseredhat:enterprise_linux_desktopredhat:enterprise_linux_serverredhat:enterprise_linux_server_ausredhat:enterprise_linux_server_eusredhat:enterprise_linux_server_tusredhat:enterprise_linux_workstationredhat:gluster_storageredhat:storageredhat:virtualizationricon:s9922lricon:s9922l_firmwaresiemens:application_processing_enginesiemens:application_processing_engine_firmwaresiemens:cp_1543-1siemens:cp_1543-1_firmwaresiemens:elan-8.2siemens:simatic_s7-1500siemens:simatic_s7-1500_firmwaresiemens:simatic_s7-1500tsiemens:simatic_s7-1500t_firmwaresiemens:wincc_open_architecturesplunk:splunk

Fraquezas (CWE)

CWE-125CWE-125

Referencias

http://heartbleed.com/(secalert@redhat.com)
http://advisories.mageia.org/MGASA-2014-0165.html(af854a3a-2127-422b-91ae-364da2661108)
http://cogentdatahub.com/ReleaseNotes.html(af854a3a-2127-422b-91ae-364da2661108)
http://heartbleed.com/(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=139722163017074&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=139757726426985&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=139757819327350&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=139757919027752&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=139758572430452&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=139765756720506&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=139774054614965&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=139774703817488&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=139808058921905&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=139817685517037&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=139817727317190&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=139817782017443&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=139824923705461&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=139824993005633&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=139833395230364&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=139835815211508&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=139835844111589&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=139836085512508&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=139842151128341&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=139843768401936&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=139869720529462&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=139869891830365&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=139889113431619&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=139889295732144&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=139905202427693&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=139905243827825&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=139905295427946&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=139905351928096&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=139905405728262&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=139905458328378&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=139905653828999&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=139905868529690&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=140015787404650&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=140075368411126&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=140724451518351&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=140752315422991&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=141287864628122&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=142660345230545&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2014-0376.html(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2014-0377.html(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2014-0378.html(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2014-0396.html(af854a3a-2127-422b-91ae-364da2661108)
http://seclists.org/fulldisclosure/2014/Apr/109(af854a3a-2127-422b-91ae-364da2661108)
http://seclists.org/fulldisclosure/2014/Apr/173(af854a3a-2127-422b-91ae-364da2661108)
http://seclists.org/fulldisclosure/2014/Apr/190(af854a3a-2127-422b-91ae-364da2661108)
http://seclists.org/fulldisclosure/2014/Apr/90(af854a3a-2127-422b-91ae-364da2661108)
http://seclists.org/fulldisclosure/2014/Apr/91(af854a3a-2127-422b-91ae-364da2661108)
http://seclists.org/fulldisclosure/2014/Dec/23(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/57347(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/57483(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/57721(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/57836(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/57966(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/57968(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/59139(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/59243(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/59347(af854a3a-2127-422b-91ae-364da2661108)
http://support.citrix.com/article/CTX140605(af854a3a-2127-422b-91ae-364da2661108)
http://www-01.ibm.com/support/docview.wss?uid=swg21670161(af854a3a-2127-422b-91ae-364da2661108)
http://www.blackberry.com/btsc/KB35882(af854a3a-2127-422b-91ae-364da2661108)
http://www.debian.org/security/2014/dsa-2896(af854a3a-2127-422b-91ae-364da2661108)
http://www.exploit-db.com/exploits/32745(af854a3a-2127-422b-91ae-364da2661108)
http://www.exploit-db.com/exploits/32764(af854a3a-2127-422b-91ae-364da2661108)
http://www.f-secure.com/en/web/labs_global/fsc-2014-1(af854a3a-2127-422b-91ae-364da2661108)
http://www.kb.cert.org/vuls/id/720951(af854a3a-2127-422b-91ae-364da2661108)
http://www.openssl.org/news/secadv_20140407.txt(af854a3a-2127-422b-91ae-364da2661108)
http://www.securityfocus.com/bid/66690(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1030026(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1030074(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1030077(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1030078(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1030079(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1030080(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1030081(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1030082(af854a3a-2127-422b-91ae-364da2661108)
http://www.splunk.com/view/SP-CAAAMB3(af854a3a-2127-422b-91ae-364da2661108)
http://www.ubuntu.com/usn/USN-2165-1(af854a3a-2127-422b-91ae-364da2661108)
http://www.us-cert.gov/ncas/alerts/TA14-098A(af854a3a-2127-422b-91ae-364da2661108)
https://bugzilla.redhat.com/show_bug.cgi?id=1084875(af854a3a-2127-422b-91ae-364da2661108)
https://code.google.com/p/mod-spdy/issues/detail?id=85(af854a3a-2127-422b-91ae-364da2661108)
https://filezilla-project.org/versions.php?type=server(af854a3a-2127-422b-91ae-364da2661108)
https://gist.github.com/chapmajs/10473815(af854a3a-2127-422b-91ae-364da2661108)

Correlacoes IOC

Sem correlacoes registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.