openssl: information disclosure in handling of TLS heartbeat extension packets
Published Apr 7, 2014 ·Due May 25, 2022
7.5
HIGHCVSS 3.1
EPSS 100.00%
Description
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.
Affected products
No data.
Configuration 2
- < 0.9.44
Configuration 3
Running on/with
- n/a
Configuration 4
- 1.1
Configuration 5
- 1.5
Running on/with
- n/a
Configuration 6
- 1.5
Running on/with
- n/a
Configuration 7
- < 8.3.3
- 3.12
Configuration 8
- 1.20
- 1.21
- 1.24
Configuration 9
- 1.15
- 1.25
Configuration 10
- 6.0
- 7.0
- 7.1
- 7.2
- 7.3
- 7.3.0.104
- 1.1.2.5
- 1.1.3.3
- 1.2.0.11
- 1.3.2.2
- 1.4.0.102
Configuration 12
- 12.04
- 12.10
- 13.10
Configuration 13
- 19
- 20
Configuration 14
- 2.1
- 2.1
- 6.0
- 6.0
- 6.0
- 6.5
- 6.5
- 6.5
- 6.0
Configuration 15
- 6.0
- 7.0
- 8.0
Configuration 16
- 16.10.3\(3794\)
Configuration 17
- 10.6.0
- 10.6.1
No data.
RHEV 3.X Hypervisor and Agents for RHEL-6
rhev-hypervisor6-0:6.5-20140118.1.3.2.el6_5
Fixed · RHSA-2014:0396
RHEV 3.X Hypervisor and Agents for RHEL-6
rhev-hypervisor6-0:6.5-20140407.0.el6ev
Fixed · RHSA-2014:0378
RHEV Manager version 3.3
spice-client-msi-0:3.3-12
Fixed · RHSA-2014:0416
Red Hat Enterprise Linux 6
openssl-0:1.0.1e-16.el6_5.7
Fixed · RHSA-2014:0376
Red Hat Storage 2.1
openssl-0:1.0.1e-16.el6_5.7
Fixed · RHSA-2014:0377
Red Hat Enterprise Linux 5
openssl
Not affected
Red Hat Enterprise Linux 5
openssl097a
Not affected
Red Hat Enterprise Linux 6
openssl098e
Not affected
Red Hat Enterprise Linux 7
openssl
Not affected
Red Hat Enterprise Linux 7
openssl098e
Not affected
Red Hat JBoss Enterprise Application Platform 5
openssl
Not affected
Red Hat JBoss Enterprise Application Platform 6
openssl
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| RHEV 3.X Hypervisor and Agents for RHEL-6 | rhev-hypervisor6-0:6.5-20140118.1.3.2.el6_5 | Fixed | RHSA-2014:0396 |
| RHEV 3.X Hypervisor and Agents for RHEL-6 | rhev-hypervisor6-0:6.5-20140407.0.el6ev | Fixed | RHSA-2014:0378 |
| RHEV Manager version 3.3 | spice-client-msi-0:3.3-12 | Fixed | RHSA-2014:0416 |
| Red Hat Enterprise Linux 6 | openssl-0:1.0.1e-16.el6_5.7 | Fixed | RHSA-2014:0376 |
| Red Hat Storage 2.1 | openssl-0:1.0.1e-16.el6_5.7 | Fixed | RHSA-2014:0377 |
| Red Hat Enterprise Linux 5 | openssl | Not affected | n/a |
| Red Hat Enterprise Linux 5 | openssl097a | Not affected | n/a |
| Red Hat Enterprise Linux 6 | openssl098e | Not affected | n/a |
| Red Hat Enterprise Linux 7 | openssl | Not affected | n/a |
| Red Hat Enterprise Linux 7 | openssl098e | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 5 | openssl | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | openssl | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue did not affect the versions of openssl as shipped with Red Hat Enterprise Linux 5, Red Hat Enterprise Linux 6.4 and earlier, Red Hat JBoss Enterprise Application Platform 5 and 6, and Red Hat JBoss Web Server 1 and 2. This issue does affect Red Hat Enterprise Linux 7 Beta, Red Hat Enterprise Linux 6.5, Red Hat Enterprise Virtualization Hypervisor 6.5, and Red Hat Storage 2.1, which provided openssl 1.0.1e. Errata have been released to correct this issue. Additional information can be found in the Red Hat Knowledgebase article: https://access.redhat.com/site/announcements/781953
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:P/I:N/A:N
Date Added
May 4, 2022
Patch Due
May 25, 2022
Required Action
Apply updates per vendor instructions.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
ActiveAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Feb 7, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (15 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 100.00% (0.99999) | 100.00th | v5 (v2026.06.15) |
| Jun 15, 2026 | 100.00% (0.99999) | 100.00th | v5 (v2026.06.15) |
| Mar 17, 2025 | 94.48% (0.94477) | 100.00th | v4 (v2025.03.14) |
| Dec 12, 2024 | 97.41% (0.97414) | 99.95th | v3 (v2023.03.01) |
| Jul 11, 2024 | 97.35% (0.97354) | 99.90th | v3 (v2023.03.01) |
| Jul 3, 2024 | 97.22% (0.97219) | 99.84th | v3 (v2023.03.01) |
| May 24, 2024 | 97.46% (0.97460) | 99.96th | v3 (v2023.03.01) |
| Apr 5, 2024 | 97.48% (0.97485) | 99.97th | v3 (v2023.03.01) |
| Feb 18, 2024 | 97.51% (0.97507) | 99.98th | v3 (v2023.03.01) |
| Jan 2, 2024 | 97.52% (0.97524) | 99.99th | v3 (v2023.03.01) |
| Nov 18, 2023 | 97.53% (0.97531) | 99.99th | v3 (v2023.03.01) |
| Nov 8, 2023 | 97.52% (0.97518) | 99.98th | v3 (v2023.03.01) |
| Mar 7, 2023 | 97.59% (0.97590) | 100.00th | v3 (v2023.03.01) |
| Mar 6, 2023 | 96.08% (0.96076) | 99.99th | v2 (v2022.01.01) |
| Feb 4, 2022 | 96.08% (0.96076) | 99.99th | v2 (v2022.01.01) |
References (133)
- http://advisories.mageia.org/MGASA-2014-0165.html Third Party Advisory
- http://blog.fox-it.com/2014/04/08/openssl-heartbleed-bug-live-blog/ Issue TrackingThird Party Advisory
- http://cogentdatahub.com/ReleaseNotes.html Release Notes
- http://download.schneider-electric.com/files?p_Doc_Ref=SEVD%202014-119-01 Broken Link
- http://git.openssl.org/gitweb/?p=openssl.git%3Ba=commit%3Bh=96db9023b881d7cd9f379b0c154650d6c108e9a3 Broken Link
- http://heartbleed.com/ Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2014-April/131221.html vendor-advisoryBroken LinkThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2014-April/131291.html vendor-advisoryBroken LinkThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136473.html vendor-advisoryMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2014-04/msg00004.html vendor-advisoryMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2014-04/msg00005.html vendor-advisoryMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2014-04/msg00061.html vendor-advisoryMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=139722163017074&w=2 vendor-advisoryMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=139757726426985&w=2 vendor-advisoryMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=139757819327350&w=2 vendor-advisoryMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=139757919027752&w=2 vendor-advisoryMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=139758572430452&w=2 vendor-advisoryMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=139765756720506&w=2 vendor-advisoryMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=139774054614965&w=2 vendor-advisoryMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=139774703817488&w=2 vendor-advisoryMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=139808058921905&w=2 vendor-advisoryMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=139817685517037&w=2 vendor-advisoryMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=139817727317190&w=2 vendor-advisoryMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=139817782017443&w=2 vendor-advisoryMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=139824923705461&w=2 vendor-advisoryMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=139824993005633&w=2 vendor-advisoryMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=139833395230364&w=2 vendor-advisoryMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=139835815211508&w=2 vendor-advisoryMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=139835844111589&w=2 vendor-advisoryMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=139836085512508&w=2 vendor-advisoryMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=139842151128341&w=2 vendor-advisoryMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=139843768401936&w=2 vendor-advisoryMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=139869720529462&w=2 vendor-advisoryMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=139869891830365&w=2 vendor-advisoryMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=139889113431619&w=2 vendor-advisoryMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=139889295732144&w=2 vendor-advisoryMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=139905202427693&w=2 vendor-advisoryMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=139905243827825&w=2 vendor-advisoryMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=139905295427946&w=2 vendor-advisoryMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=139905351928096&w=2 vendor-advisoryMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=139905405728262&w=2 vendor-advisoryMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=139905458328378&w=2 vendor-advisoryMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=139905653828999&w=2 vendor-advisoryMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=139905868529690&w=2 vendor-advisoryMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=140015787404650&w=2 vendor-advisoryMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=140075368411126&w=2 vendor-advisoryMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=140724451518351&w=2 vendor-advisoryMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=140752315422991&w=2 vendor-advisoryMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=141287864628122&w=2 vendor-advisoryMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=142660345230545&w=2 vendor-advisoryMailing ListThird Party Advisory
- http://public.support.unisys.com/common/public/vulnerability/NVD_Detail_Rpt.aspx?ID=1 Third Party Advisory
- http://public.support.unisys.com/common/public/vulnerability/NVD_Detail_Rpt.aspx?ID=3 Permissions RequiredThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-0376.html vendor-advisoryThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-0377.html vendor-advisoryThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-0378.html vendor-advisoryThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-0396.html vendor-advisoryThird Party Advisory
- http://seclists.org/fulldisclosure/2014/Apr/109 mailing-listMailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2014/Apr/173 mailing-listMailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2014/Apr/190 mailing-listMailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2014/Apr/90 mailing-listMailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2014/Apr/91 mailing-listMailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2014/Dec/23 mailing-listMailing ListThird Party Advisory
- http://secunia.com/advisories/57347 third-party-advisoryBroken LinkThird Party Advisory
- http://secunia.com/advisories/57483 third-party-advisoryBroken LinkThird Party Advisory
- http://secunia.com/advisories/57721 third-party-advisoryBroken LinkThird Party Advisory
- http://secunia.com/advisories/57836 third-party-advisoryBroken LinkThird Party Advisory
- http://secunia.com/advisories/57966 third-party-advisoryBroken LinkThird Party Advisory
- http://secunia.com/advisories/57968 third-party-advisoryBroken LinkThird Party Advisory
- http://secunia.com/advisories/59139 third-party-advisoryBroken LinkThird Party Advisory
- http://secunia.com/advisories/59243 third-party-advisoryBroken LinkThird Party Advisory
- http://secunia.com/advisories/59347 third-party-advisoryBroken LinkThird Party Advisory
- http://support.citrix.com/article/CTX140605 Third Party Advisory
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140409-heartbleed vendor-advisoryThird Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=isg400001841 Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=isg400001843 Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004661 Third Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21670161 Broken Link
- http://www.apcmedia.com/salestools/SJHN-7RKGNM/SJHN-7RKGNM_R4_EN.pdf Broken LinkThird Party Advisory
- http://www.blackberry.com/btsc/KB35882 Broken Link
- http://www.debian.org/security/2014/dsa-2896 vendor-advisoryMailing ListThird Party Advisory
- http://www.exploit-db.com/exploits/32745 exploitThird Party AdvisoryVDB Entry
- http://www.exploit-db.com/exploits/32764 exploitThird Party AdvisoryVDB Entry
- http://www.f-secure.com/en/web/labs_global/fsc-2014-1 Broken LinkThird Party Advisory
- http://www.getchef.com/blog/2014/04/09/chef-server-11-0-12-release/ Release Notes
- http://www.getchef.com/blog/2014/04/09/chef-server-heartbleed-cve-2014-0160-releases/ Third Party Advisory
- http://www.getchef.com/blog/2014/04/09/enterprise-chef-1-4-9-release/ Release Notes
- http://www.getchef.com/blog/2014/04/09/enterprise-chef-11-1-3-release/ Release Notes
- http://www.innominate.com/data/downloads/manuals/mdm_1.5.2.1_Release_Notes.pdf Not Applicable
- http://www.kb.cert.org/vuls/id/720951 third-party-advisoryThird Party AdvisoryUS Government Resource
- http://www.kerio.com/support/kerio-control/release-history Broken LinkThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:062 vendor-advisoryBroken LinkThird Party Advisory
- http://www.openssl.org/news/secadv_20140407.txt Broken LinkVendor Advisory
- http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html PatchThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/opensslheartbleedcve-2014-0160-2188454.html PatchThird Party Advisory
- http://www.securityfocus.com/archive/1/534161/100/0/threaded mailing-listBroken LinkNot ApplicableThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/66690 vdb-entryBroken LinkThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1030026 vdb-entryBroken LinkThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1030074 vdb-entryBroken LinkThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1030077 vdb-entryBroken LinkThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1030078 vdb-entryBroken LinkThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1030079 vdb-entryBroken LinkThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1030080 vdb-entryBroken LinkThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1030081 vdb-entryBroken LinkThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1030082 vdb-entryBroken LinkThird Party AdvisoryVDB Entry
- http://www.splunk.com/view/SP-CAAAMB3 Third Party Advisory
- http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20160512_00 Third Party Advisory
- http://www.ubuntu.com/usn/USN-2165-1 vendor-advisoryThird Party Advisory
- http://www.us-cert.gov/ncas/alerts/TA14-098A third-party-advisoryThird Party AdvisoryUS Government Resource
- http://www.vmware.com/security/advisories/VMSA-2014-0012.html Broken Link
- http://www.websense.com/support/article/kbarticle/Vulnerabilities-resolved-in-TRITON-APX-Version-8-0 Broken Link
- https://access.redhat.com/security/cve/CVE-2014-0160 Vendor Advisory
- https://blog.torproject.org/blog/openssl-bug-cve-2014-0160 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=1084875 Issue TrackingThird Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-635659.pdf Third Party Advisory
- https://code.google.com/p/mod-spdy/issues/detail?id=85 Issue Tracking
- https://filezilla-project.org/versions.php?type=server Release Notes
- https://gist.github.com/chapmajs/10473815 Exploit
- https://h20566.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?spf_p.tpst=kbDocDisplay&spf_p.prp_kbDocDisplay=wsrp-navigationalState%3DdocId%253Demr_na-c04260637-4%257CdocLocale%253Den_US%257CcalledBy%253DSearch_Result&javax.portlet.begCacheTok=com.vignette.cachetoken&javax.portlet.endCacheTok=com.vignette.cachetoken vendor-advisoryBroken Link
- https://lists.apache.org/thread.html/ba661b0edd913b39ff129a32d855620dd861883ade05fd88a8ce517d%40%3Cdev.tomcat.apache.org%3E mailing-listMailing ListPatchThird Party Advisory
- https://lists.apache.org/thread.html/f8e0814e11c7f21f42224b6de111cb3f5e5ab5c15b78924c516d4ec2%40%3Cdev.tomcat.apache.org%3E mailing-listMailing ListPatchThird Party Advisory
- https://lists.apache.org/thread.html/re3b72cbb13e1dfe85c4a06959a3b6ca6d939b407ecca80db12b54220%40%3Cdev.tomcat.apache.org%3E mailing-listMailing ListPatchThird Party Advisory
- https://lists.apache.org/thread.html/rf8e8c091182b45daa50d3557cad9b10bb4198e3f08cf8f1c66a1b08d%40%3Cdev.tomcat.apache.org%3E mailing-listMailing ListPatchThird Party Advisory
- https://lists.balabit.hu/pipermail/syslog-ng-announce/2014-April/000184.html mailing-listMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2014-0160
- https://sku11army.blogspot.com/2020/01/heartbleed-hearts-continue-to-bleed.html ExploitPermissions RequiredThird Party Advisory
- https://support.f5.com/kb/en-us/solutions/public/15000/100/sol15159.html Third Party Advisory
- https://support.f5.com/kb/en-us/solutions/public/15000/100/sol15159.html?sr=36517217 Third Party Advisory
- https://www.cert.fi/en/reports/2014/vulnerability788210.html Not ApplicableThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2014-0160 government-resourceUS Government Resource
- https://www.cve.org/CVERecord?id=CVE-2014-0160
- https://www.mitel.com/en-ca/support/security-advisories/mitel-product-security-advisory-17-0008 Third Party Advisory
- https://yunus-shn.medium.com/ricon-industrial-cellular-router-heartbleed-attack-2634221c02bd Broken LinkExploitThird Party Advisory
Change history (0)
No recorded changes yet.