openssl: Buffer overflow via DTLS invalid fragment
Published Jun 5, 2014
6.8
MEDIUMCVSS 2.0
EPSS 99.98%
Description
The dtls1_reassemble_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly validate fragment lengths in DTLS ClientHello messages, which allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via a long non-initial fragment.
Affected products
No data.
Configuration 1
Configuration 4
- 19
- 20
No data.
Red Hat Enterprise Linux 6
openssl-0:1.0.1e-16.el6_5.14
Fixed · RHSA-2014:0625
Red Hat Enterprise Linux 7
openssl-1:1.0.1e-34.el7_0.3
Fixed · RHSA-2014:0679
Red Hat Storage 2.1
openssl-0:1.0.1e-16.el6_5.14
Fixed · RHSA-2014:0628
Red Hat Enterprise Linux 5
openssl
Not affected
Red Hat Enterprise Linux 5
openssl097a
Not affected
Red Hat Enterprise Linux 6
guest-images
Not affected
Red Hat Enterprise Linux 6
openssl098e
Not affected
Red Hat Enterprise Linux 7
openssl098e
Not affected
Red Hat Enterprise Virtualization 3
mingw-virt-viewer
Not affected
Red Hat Enterprise Virtualization 3
rhev-hypervisor
Not affected
Red Hat JBoss Enterprise Application Platform 5
openssl
Not affected
Red Hat JBoss Enterprise Application Platform 6
openssl
Not affected
Red Hat JBoss Enterprise Web Server 1
openssl
Not affected
Red Hat JBoss Enterprise Web Server 2
openssl
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | openssl-0:1.0.1e-16.el6_5.14 | Fixed | RHSA-2014:0625 |
| Red Hat Enterprise Linux 7 | openssl-1:1.0.1e-34.el7_0.3 | Fixed | RHSA-2014:0679 |
| Red Hat Storage 2.1 | openssl-0:1.0.1e-16.el6_5.14 | Fixed | RHSA-2014:0628 |
| Red Hat Enterprise Linux 5 | openssl | Not affected | n/a |
| Red Hat Enterprise Linux 5 | openssl097a | Not affected | n/a |
| Red Hat Enterprise Linux 6 | guest-images | Not affected | n/a |
| Red Hat Enterprise Linux 6 | openssl098e | Not affected | n/a |
| Red Hat Enterprise Linux 7 | openssl098e | Not affected | n/a |
| Red Hat Enterprise Virtualization 3 | mingw-virt-viewer | Not affected | n/a |
| Red Hat Enterprise Virtualization 3 | rhev-hypervisor | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 5 | openssl | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | openssl | Not affected | n/a |
| Red Hat JBoss Enterprise Web Server 1 | openssl | Not affected | n/a |
| Red Hat JBoss Enterprise Web Server 2 | openssl | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue does not affect the version of openssl as shipped with Red Hat Enterprise Linux 5. This issue does not affect the version of openssl098e as shipped with Red Hat Enterprise Linux 6.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (23 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 99.98% (0.99977) | 99.98th | v5 (v2026.06.15) |
| Jun 15, 2026 | 99.98% (0.99977) | 99.98th | v5 (v2026.06.15) |
| Dec 11, 2025 | 92.75% (0.92751) | 99.74th | v4 (v2025.03.14) |
| Oct 28, 2025 | 90.91% (0.90912) | 99.61th | v4 (v2025.03.14) |
| Oct 27, 2025 | 92.32% (0.92320) | 99.71th | v4 (v2025.03.14) |
| Oct 1, 2025 | 90.91% (0.90912) | 99.63th | v4 (v2025.03.14) |
| Jul 30, 2025 | 92.32% (0.92320) | 99.71th | v4 (v2025.03.14) |
| Mar 27, 2025 | 90.53% (0.90527) | 99.59th | v4 (v2025.03.14) |
| Mar 20, 2025 | 88.99% (0.88987) | 99.52th | v4 (v2025.03.14) |
| Mar 19, 2025 | 90.53% (0.90527) | 99.60th | v4 (v2025.03.14) |
| Mar 17, 2025 | 88.99% (0.88987) | 99.51th | v4 (v2025.03.14) |
| Dec 12, 2024 | 96.65% (0.96646) | 99.69th | v3 (v2023.03.01) |
| Jun 3, 2024 | 96.80% (0.96803) | 99.69th | v3 (v2023.03.01) |
| Apr 17, 2024 | 96.87% (0.96874) | 99.69th | v3 (v2023.03.01) |
| Mar 1, 2024 | 96.81% (0.96806) | 99.66th | v3 (v2023.03.01) |
| Jan 16, 2024 | 96.66% (0.96662) | 99.56th | v3 (v2023.03.01) |
| Nov 30, 2023 | 96.48% (0.96482) | 99.47th | v3 (v2023.03.01) |
| Nov 8, 2023 | 96.52% (0.96516) | 99.47th | v3 (v2023.03.01) |
| Oct 10, 2023 | 96.76% (0.96761) | 99.54th | v3 (v2023.03.01) |
| May 13, 2023 | 96.98% (0.96976) | 99.57th | v3 (v2023.03.01) |
| Mar 7, 2023 | 97.07% (0.97074) | 99.57th | v3 (v2023.03.01) |
| Mar 6, 2023 | 75.51% (0.75509) | 99.36th | v2 (v2022.01.01) |
| Feb 4, 2022 | 75.51% (0.75509) | 99.21th | v2 (v2022.01.01) |
References (130)
- http://aix.software.ibm.com/aix/efixes/security/openssl_advisory9.asc x_refsource_CONFIRMThird Party Advisory
- http://h30499.www3.hp.com/t5/HP-Security-Research-Blog/Once-Bled-Twice-Shy-OpenSSL-CVE-2014-0195/ba-p/6501048 x_refsource_MISCBroken Link
- http://h30499.www3.hp.com/t5/HP-Security-Research-Blog/ZDI-14-173-CVE-2014-0195-OpenSSL-DTLS-Fragment-Out-of-Bounds/ba-p/6501002 x_refsource_MISCBroken Link
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10629 x_refsource_CONFIRMThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136470.html vendor-advisoryx_refsource_FEDORAMailing ListThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136473.html vendor-advisoryx_refsource_FEDORAMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00016.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=140266410314613&w=2 vendor-advisoryx_refsource_HPIssue TrackingMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=140317760000786&w=2 vendor-advisoryx_refsource_HPIssue TrackingMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=140389274407904&w=2 vendor-advisoryx_refsource_HPIssue TrackingMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=140389355508263&w=2 vendor-advisoryx_refsource_HPIssue TrackingMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=140431828824371&w=2 vendor-advisoryx_refsource_HPIssue TrackingMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=140448122410568&w=2 vendor-advisoryx_refsource_HPIssue TrackingMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=140482916501310&w=2 vendor-advisoryx_refsource_HPIssue TrackingMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=140491231331543&w=2 vendor-advisoryx_refsource_HPIssue TrackingMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=140499827729550&w=2 vendor-advisoryx_refsource_HPIssue TrackingMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=140621259019789&w=2 vendor-advisoryx_refsource_HPIssue TrackingMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=140752315422991&w=2 vendor-advisoryx_refsource_HPIssue TrackingMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=140904544427729&w=2 vendor-advisoryx_refsource_HPIssue TrackingMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=142660345230545&w=2 vendor-advisoryx_refsource_HPIssue TrackingMailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2014/Dec/23 mailing-listx_refsource_FULLDISCMailing ListThird Party Advisory
- http://secunia.com/advisories/58337 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/58615 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/58660 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/58713 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/58714 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/58743 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/58883 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/58939 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/58945 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/58977 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59040 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59126 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59162 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59175 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59188 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59189 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59192 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59223 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59287 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59300 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59301 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59305 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59306 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59310 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59342 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59364 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59365 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59413 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59429 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59437 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59441 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59449 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59450 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59451 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59454 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59490 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59491 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59514 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59518 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59528 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59530 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59587 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59655 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59659 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59666 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59669 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59721 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59784 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59895 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59990 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/60571 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/61254 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://security.gentoo.org/glsa/glsa-201407-05.xml vendor-advisoryx_refsource_GENTOOThird Party Advisory
- http://support.apple.com/kb/HT6443 x_refsource_CONFIRMThird Party Advisory
- http://support.citrix.com/article/CTX140876 x_refsource_CONFIRMThird Party Advisory
- http://support.f5.com/kb/en-us/solutions/public/15000/300/sol15356.html x_refsource_CONFIRMThird Party Advisory
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140605-openssl vendor-advisoryx_refsource_CISCOThird Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=isg400001841 x_refsource_CONFIRMThird Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=isg400001843 x_refsource_CONFIRMThird Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=nas8N1020163 x_refsource_CONFIRMThird Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21673137 x_refsource_CONFIRMBroken Link
- http://www-01.ibm.com/support/docview.wss?uid=swg21675821 x_refsource_CONFIRMThird Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21676035 x_refsource_CONFIRMBroken Link
- http://www-01.ibm.com/support/docview.wss?uid=swg21676062 x_refsource_CONFIRMThird Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21676071 x_refsource_CONFIRMThird Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21676419 x_refsource_CONFIRMThird Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21676644 x_refsource_CONFIRMThird Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21676879 x_refsource_CONFIRMBroken Link
- http://www-01.ibm.com/support/docview.wss?uid=swg21676889 x_refsource_CONFIRMBroken Link
- http://www-01.ibm.com/support/docview.wss?uid=swg21677527 x_refsource_CONFIRMBroken Link
- http://www-01.ibm.com/support/docview.wss?uid=swg21677695 x_refsource_CONFIRMThird Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21677828 x_refsource_CONFIRMThird Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21678167 x_refsource_CONFIRMThird Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21678289 x_refsource_CONFIRMThird Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21683332 x_refsource_CONFIRMThird Party Advisory
- http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095754 x_refsource_CONFIRMThird Party Advisory
- http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095755 x_refsource_CONFIRMThird Party Advisory
- http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095756 x_refsource_CONFIRMThird Party Advisory
- http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095757 x_refsource_CONFIRMThird Party Advisory
- http://www.blackberry.com/btsc/KB36051 x_refsource_CONFIRMThird Party Advisory
- http://www.f-secure.com/en/web/labs_global/fsc-2014-6 x_refsource_CONFIRMThird Party Advisory
- http://www.fortiguard.com/advisory/FG-IR-14-018/ x_refsource_CONFIRMThird Party Advisory
- http://www.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-345106.htm x_refsource_CONFIRMThird Party Advisory
- http://www.ibm.com/support/docview.wss?uid=swg21676356 x_refsource_CONFIRMThird Party Advisory
- http://www.ibm.com/support/docview.wss?uid=swg21676793 x_refsource_CONFIRMBroken Link
- http://www.ibm.com/support/docview.wss?uid=swg24037783 x_refsource_CONFIRMThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2014:106 vendor-advisoryx_refsource_MANDRIVABroken Link
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:062 vendor-advisoryx_refsource_MANDRIVABroken Link
- http://www.openssl.org/news/secadv_20140605.txt x_refsource_CONFIRMVendor Advisory
- http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html x_refsource_CONFIRMThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html x_refsource_CONFIRMThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html x_refsource_CONFIRMThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html x_refsource_CONFIRMThird Party Advisory
- http://www.securityfocus.com/archive/1/534161/100/0/threaded mailing-listx_refsource_BUGTRAQThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/67900 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1030337 vdb-entryx_refsource_SECTRACKBroken LinkThird Party AdvisoryVDB Entry
- http://www.vmware.com/security/advisories/VMSA-2014-0006.html x_refsource_CONFIRMThird Party Advisory
- http://www.vmware.com/security/advisories/VMSA-2014-0012.html x_refsource_CONFIRMThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2014-0195 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1103598 x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commit%3Bh=1632ef744872edc2aa2a53d487d3e79c965a4ad3 x_refsource_CONFIRM
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05301946 x_refsource_CONFIRMThird Party Advisory
- https://kb.bluecoat.com/index?page=content&id=SA80 x_refsource_CONFIRMBroken Link
- https://kc.mcafee.com/corporate/index?page=content&id=SB10075 x_refsource_CONFIRMBroken Link
- https://nvd.nist.gov/vuln/detail/CVE-2014-0195
- https://www.cve.org/CVERecord?id=CVE-2014-0195
- https://www.novell.com/support/kb/doc.php?id=7015271 x_refsource_CONFIRMThird Party Advisory
- https://www.openssl.org/news/secadv_20140605.txt
Change history (0)
No recorded changes yet.