OpenSSL vulnerability (CVE-2014-3513)
Release date:
Updated on:
Affected Systems:
OpenSSL Project OpenSSL <1.0.1j
Description:
Bugtraq id: 70584
CVE (CAN) ID: CVE-2014-3513
OpenSSL is an open-source SSL implementation that implements high-strength encryption for network communication. It is widely used in various network applications.
The memory leakage vulnerability exists in the implementation of dtls srtp extension data parsing in OpenSSL versions earlier than 1.0.1j. By sending a series of constructed handshake information, OpenSSL cannot release 64 KB of memory, leading to memory leakage and DOS.
<* Source: OpenSSL Project
Link: https://www.openssl.org/news/secadv_20141015.txt
*>
Suggestion:
Vendor patch:
OpenSSL Project
---------------
The OpenSSL Project has released a Security Bulletin (secadv_20151115) and the corresponding patch:
Secadv_20151115: OpenSSL Security Advisory [15 Oct 2014]
Link: https://www.openssl.org/news/secadv_20141015.txt
OpenSSL TLS heartbeat read remote information leakage (CVE-2014-0160)
Severe OpenSSL bug allows attackers to read 64 KB of memory, fixed in half an hour in Debian
OpenSSL "heartbleed" Security Vulnerability
Provides FTP + SSL/TLS authentication through OpenSSL and implements secure data transmission.
OpenSSL details: click here
OpenSSL: click here
This article permanently updates the link address: