CVE-2014-8176

NameCVE-2014-8176
DescriptionThe dtls1_clear_queues function in ssl/d1_lib.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h frees data structures without considering that application data can arrive between a ChangeCipherSpec message and a Finished message, which allows remote DTLS peers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unexpected application data.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDLA-247-1, DSA-3287-1
NVD severityhigh

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
openssl (PTS)jessie1.0.1t-1+deb8u8fixed
jessie (security)1.0.1t-1+deb8u12fixed
stretch1.1.0k-1~deb9u1fixed
stretch (security)1.1.0l-1~deb9u1fixed
buster1.1.1c-1fixed
buster (security)1.1.1d-0+deb10u2fixed
bullseye, sid1.1.1d-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
opensslsource(unstable)1.0.1h-1
opensslsourcejessie1.0.1k-3+deb8u1DSA-3287-1
opensslsourcesqueeze0.9.8o-4squeeze21DLA-247-1
opensslsourcewheezy1.0.1e-2+deb7u17DSA-3287-1

Notes

http://openssl.org/news/secadv/20150611.txt

Search for package or bug name: Reporting problems