CVE-2014-0198

Description

The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, does not properly manage a buffer pointer during certain recursive calls, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors that trigger an alert condition.

Risk Information

Base Score
8.1
MODERATE
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
30.893

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities fixed in OpenSSL (x64) 1.0.0mWindows
Multiple vulnerabilities fixed in OpenSSL (x64) 1.0.1hWindows
Secure Socket Layer (SSL) cryptographic library and tools (USN-2192-1) libssl1.0.0_1.0.1f-1ubuntu2.16_i386.debLinux
Secure Socket Layer (SSL) cryptographic library and tools (USN-2192-1) libssl1.0.0_1.0.1f-1ubuntu2.16_amd64.debLinux
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products For Cisco IOSNCM
NULL Pointer Dereference Vulnerability (CVE-2014-0198)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-1706090Security Update for Cisco IOS Amsterdam-17.2.1r

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234