Return to CVE list

CVE-2014-0160

7.5
Critical

OpenSSL Information Disclosure Vulnerability

secalert@redhat.com
Deferred

Description

The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.

References

secalert@redhat.com
http://heartbleed.com/
af854a3a-2127-422b-91ae-364da2661108
http://advisories.mageia.org/MGASA-2014-0165.html
af854a3a-2127-422b-91ae-364da2661108
http://cogentdatahub.com/ReleaseNotes.html
af854a3a-2127-422b-91ae-364da2661108
http://heartbleed.com/
af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=139722163017074&w=2
af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=139757726426985&w=2
af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=139757819327350&w=2
af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=139757919027752&w=2
af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=139758572430452&w=2
af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=139765756720506&w=2
af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=139774054614965&w=2
af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=139774703817488&w=2
af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=139808058921905&w=2
af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=139817685517037&w=2
af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=139817727317190&w=2
af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=139817782017443&w=2
af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=139824923705461&w=2
af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=139824993005633&w=2
af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=139833395230364&w=2
af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=139835815211508&w=2
af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=139835844111589&w=2
af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=139836085512508&w=2
af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=139842151128341&w=2
af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=139843768401936&w=2
af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=139869720529462&w=2
af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=139869891830365&w=2
af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=139889113431619&w=2
af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=139889295732144&w=2
af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=139905202427693&w=2
af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=139905243827825&w=2
af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=139905295427946&w=2
af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=139905351928096&w=2
af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=139905405728262&w=2
af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=139905458328378&w=2
af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=139905653828999&w=2
af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=139905868529690&w=2
af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=140015787404650&w=2
af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=140075368411126&w=2
af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=140724451518351&w=2
af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=140752315422991&w=2
af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=141287864628122&w=2
af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=142660345230545&w=2
af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=142660345230545&w=2
af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=142660345230545&w=2
af854a3a-2127-422b-91ae-364da2661108
http://marc.info/?l=bugtraq&m=142660345230545&w=2
af854a3a-2127-422b-91ae-364da2661108
http://rhn.redhat.com/errata/RHSA-2014-0376.html
af854a3a-2127-422b-91ae-364da2661108
http://rhn.redhat.com/errata/RHSA-2014-0377.html
af854a3a-2127-422b-91ae-364da2661108
http://rhn.redhat.com/errata/RHSA-2014-0378.html
af854a3a-2127-422b-91ae-364da2661108
http://rhn.redhat.com/errata/RHSA-2014-0396.html
af854a3a-2127-422b-91ae-364da2661108
http://seclists.org/fulldisclosure/2014/Apr/109
af854a3a-2127-422b-91ae-364da2661108
http://seclists.org/fulldisclosure/2014/Apr/173
af854a3a-2127-422b-91ae-364da2661108
http://seclists.org/fulldisclosure/2014/Apr/190
af854a3a-2127-422b-91ae-364da2661108
http://seclists.org/fulldisclosure/2014/Apr/90
af854a3a-2127-422b-91ae-364da2661108
http://seclists.org/fulldisclosure/2014/Apr/91
af854a3a-2127-422b-91ae-364da2661108
http://seclists.org/fulldisclosure/2014/Dec/23
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/57347
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/57483
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/57721
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/57836
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/57966
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/57968
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/59139
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/59243
af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/59347
af854a3a-2127-422b-91ae-364da2661108
http://support.citrix.com/article/CTX140605
af854a3a-2127-422b-91ae-364da2661108
http://www.blackberry.com/btsc/KB35882
af854a3a-2127-422b-91ae-364da2661108
http://www.debian.org/security/2014/dsa-2896
af854a3a-2127-422b-91ae-364da2661108
http://www.exploit-db.com/exploits/32745
af854a3a-2127-422b-91ae-364da2661108
http://www.exploit-db.com/exploits/32764
af854a3a-2127-422b-91ae-364da2661108
http://www.f-secure.com/en/web/labs_global/fsc-2014-1
af854a3a-2127-422b-91ae-364da2661108
http://www.kb.cert.org/vuls/id/720951
af854a3a-2127-422b-91ae-364da2661108
http://www.openssl.org/news/secadv_20140407.txt
af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/66690
af854a3a-2127-422b-91ae-364da2661108
http://www.securitytracker.com/id/1030026
af854a3a-2127-422b-91ae-364da2661108
http://www.securitytracker.com/id/1030074
af854a3a-2127-422b-91ae-364da2661108
http://www.securitytracker.com/id/1030077
af854a3a-2127-422b-91ae-364da2661108
http://www.securitytracker.com/id/1030078
af854a3a-2127-422b-91ae-364da2661108
http://www.securitytracker.com/id/1030079
af854a3a-2127-422b-91ae-364da2661108
http://www.securitytracker.com/id/1030080
af854a3a-2127-422b-91ae-364da2661108
http://www.securitytracker.com/id/1030081
af854a3a-2127-422b-91ae-364da2661108
http://www.securitytracker.com/id/1030082
af854a3a-2127-422b-91ae-364da2661108
http://www.splunk.com/view/SP-CAAAMB3
af854a3a-2127-422b-91ae-364da2661108
http://www.ubuntu.com/usn/USN-2165-1
af854a3a-2127-422b-91ae-364da2661108
http://www.us-cert.gov/ncas/alerts/TA14-098A
af854a3a-2127-422b-91ae-364da2661108
https://bugzilla.redhat.com/show_bug.cgi?id=1084875
af854a3a-2127-422b-91ae-364da2661108
https://code.google.com/p/mod-spdy/issues/detail?id=85
af854a3a-2127-422b-91ae-364da2661108
https://filezilla-project.org/versions.php?type=server
af854a3a-2127-422b-91ae-364da2661108
https://gist.github.com/chapmajs/10473815