CVE-2014-8176

UnknownEPSS 16.59%

Last modified

CVE-2014-8176 is a vulnerability of currently unknown severity. The dtls1_clear_queues function in ssl/d1_lib.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h frees data structures without considering that application data can arrive between a ChangeCipherSpec message and a Finished message, which allows remote DTLS peers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unexpected application data.. EPSS estimates a 16.59% chance of exploitation in the next 30 days.

Description

The dtls1_clear_queues function in ssl/d1_lib.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h frees data structures without considering that application data can arrive between a ChangeCipherSpec message and a Finished message, which allows remote DTLS peers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unexpected application data.

Metrics

EPSS Probability
16.59%

96.6th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
OpensslOpenssl<= 0.9.8z
OpensslOpenssl1.0.0
OpensslOpenssl1.0.0a
OpensslOpenssl1.0.0b
OpensslOpenssl1.0.0c
OpensslOpenssl1.0.0d
OpensslOpenssl1.0.0e
OpensslOpenssl1.0.0f
OpensslOpenssl1.0.0g
OpensslOpenssl1.0.0h
OpensslOpenssl1.0.0i
OpensslOpenssl1.0.0j
OpensslOpenssl1.0.0k
OpensslOpenssl1.0.0l
OpensslOpenssl1.0.1
OpensslOpenssl1.0.1a
OpensslOpenssl1.0.1b
OpensslOpenssl1.0.1c
OpensslOpenssl1.0.1d
OpensslOpenssl1.0.1e
OpensslOpenssl1.0.1f
OpensslOpenssl1.0.1g

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2014-8176?
The dtls1_clear_queues function in ssl/d1_lib.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h frees data structures without considering that application data can arrive between a ChangeCipherSpec message and a Finished message, which allows remote DTLS peers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unexpected application data.
How severe is CVE-2014-8176?
Severity scoring for CVE-2014-8176 is pending analysis. The EPSS model estimates a 16.59% probability of exploitation in the next 30 days.
How do I fix CVE-2014-8176?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2014-8176?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST