Unrated severityNVD Advisory· Published Jun 12, 2015· Updated May 6, 2026
CVE-2014-8176
CVE-2014-8176
Description
The dtls1_clear_queues function in ssl/d1_lib.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h frees data structures without considering that application data can arrive between a ChangeCipherSpec message and a Finished message, which allows remote DTLS peers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unexpected application data.
Affected products
31cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*+ 29 more
- cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*range: <=0.9.8z
- cpe:2.3:a:openssl:openssl:1.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:openssl:openssl:1.0.0a:*:*:*:*:*:*:*
- cpe:2.3:a:openssl:openssl:1.0.0b:*:*:*:*:*:*:*
- cpe:2.3:a:openssl:openssl:1.0.0:beta1:*:*:*:*:*:*
- cpe:2.3:a:openssl:openssl:1.0.0:beta2:*:*:*:*:*:*
- cpe:2.3:a:openssl:openssl:1.0.0:beta3:*:*:*:*:*:*
- cpe:2.3:a:openssl:openssl:1.0.0:beta4:*:*:*:*:*:*
- cpe:2.3:a:openssl:openssl:1.0.0:beta5:*:*:*:*:*:*
- cpe:2.3:a:openssl:openssl:1.0.0c:*:*:*:*:*:*:*
- cpe:2.3:a:openssl:openssl:1.0.0d:*:*:*:*:*:*:*
- cpe:2.3:a:openssl:openssl:1.0.0e:*:*:*:*:*:*:*
- cpe:2.3:a:openssl:openssl:1.0.0f:*:*:*:*:*:*:*
- cpe:2.3:a:openssl:openssl:1.0.0g:*:*:*:*:*:*:*
- cpe:2.3:a:openssl:openssl:1.0.0h:*:*:*:*:*:*:*
- cpe:2.3:a:openssl:openssl:1.0.0i:*:*:*:*:*:*:*
- cpe:2.3:a:openssl:openssl:1.0.0j:*:*:*:*:*:*:*
- cpe:2.3:a:openssl:openssl:1.0.0k:*:*:*:*:*:*:*
- cpe:2.3:a:openssl:openssl:1.0.0l:*:*:*:*:*:*:*
- cpe:2.3:a:openssl:openssl:1.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:openssl:openssl:1.0.1a:*:*:*:*:*:*:*
- cpe:2.3:a:openssl:openssl:1.0.1b:*:*:*:*:*:*:*
- cpe:2.3:a:openssl:openssl:1.0.1:beta1:*:*:*:*:*:*
- cpe:2.3:a:openssl:openssl:1.0.1:beta2:*:*:*:*:*:*
- cpe:2.3:a:openssl:openssl:1.0.1:beta3:*:*:*:*:*:*
- cpe:2.3:a:openssl:openssl:1.0.1c:*:*:*:*:*:*:*
- cpe:2.3:a:openssl:openssl:1.0.1d:*:*:*:*:*:*:*
- cpe:2.3:a:openssl:openssl:1.0.1e:*:*:*:*:*:*:*
- cpe:2.3:a:openssl:openssl:1.0.1f:*:*:*:*:*:*:*
- cpe:2.3:a:openssl:openssl:1.0.1g:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
21- rt.openssl.org/Ticket/Display.htmlnvdExploit
- h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplaynvdThird Party Advisory
- www.openssl.org/news/secadv_20150611.txtnvdVendor Advisory
- fortiguard.com/advisory/openssl-vulnerabilities-june-2015nvd
- ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2015-008.txt.ascnvd
- lists.opensuse.org/opensuse-security-announce/2015-07/msg00007.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2015-07/msg00037.htmlnvd
- rhn.redhat.com/errata/RHSA-2015-1115.htmlnvd
- rhn.redhat.com/errata/RHSA-2016-2957.htmlnvd
- tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150612-opensslnvd
- www.debian.org/security/2015/dsa-3287nvd
- www.fortiguard.com/advisory/openssl-vulnerabilities-june-2015nvd
- www.securityfocus.com/bid/75159nvd
- www.securitytracker.com/id/1032564nvd
- www.ubuntu.com/usn/USN-2639-1nvd
- bto.bluecoat.com/security-advisory/sa98nvd
- cert-portal.siemens.com/productcert/pdf/ssa-412672.pdfnvd
- github.com/openssl/openssl/commit/470990fee0182566d439ef7e82d1abf18b7085d7nvd
- kc.mcafee.com/corporate/indexnvd
- openssl.org/news/secadv/20150611.txtnvd
- security.gentoo.org/glsa/201506-02nvd
News mentions
0No linked articles in our index yet.