CVE-2014-8176

Description

The dtls1_clear_queues function in ssl/d1_lib.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h frees data structures without considering that application data can arrive between a ChangeCipherSpec message and a Finished message, which allows remote DTLS peers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unexpected application data.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
23.776

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities fixed in OpenSSL (x64) 0.9.8zaWindows
Multiple vulnerabilities fixed in OpenSSL (x64) 1.0.0mWindows
Multiple vulnerabilities fixed in OpenSSL (x64) 1.0.1hWindows
Multiple Vulnerabilities in OpenSSL (June 2015) Affecting Cisco Products For Cisco IOS XE SoftwareNCM
Multiple Vulnerabilities in OpenSSL (June 2015) Affecting Cisco Products For Cisco Jabber for MacNCM
Multiple Vulnerabilities in OpenSSL (June 2015) Affecting Cisco Products For Cisco NX-OS SoftwareNCM
Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2014-8176)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-1706107Security Update for Cisco IOS XE Software 5.2(1)SV5(1.3a)
PATCH-1706149Security Update for Cisco NX-OS Software 4.1(3a)UCSM

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234