openssl: SSL_MODE_RELEASE_BUFFERS NULL pointer dereference in do_ssl3_write()
Published May 6, 2014
4.3
MEDIUMCVSS 2.0
EPSS 43.83%
Description
The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, does not properly manage a buffer pointer during certain recursive calls, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors that trigger an alert condition.
Affected products
No data.
Configuration 3
- 19
- 20
Configuration 4
- 6.0
- 7.0
- 8.0
Configuration 5
- 12.3
- 13.1
- 12
- 12
- 12
- 12
No data.
Red Hat Enterprise Linux 6
openssl-0:1.0.1e-16.el6_5.14
Fixed · RHSA-2014:0625
Red Hat Enterprise Linux 7
openssl-1:1.0.1e-34.el7_0.3
Fixed · RHSA-2014:0679
Red Hat Storage 2.1
openssl-0:1.0.1e-16.el6_5.14
Fixed · RHSA-2014:0628
Red Hat Enterprise Linux 5
openssl
Not affected
Red Hat Enterprise Linux 5
openssl097a
Not affected
Red Hat Enterprise Linux 6
guest-images
Not affected
Red Hat Enterprise Linux 6
openssl098e
Not affected
Red Hat Enterprise Linux 7
openssl098e
Not affected
Red Hat Enterprise Virtualization 3
mingw-virt-viewer
Not affected
Red Hat JBoss Enterprise Application Platform 5
openssl
Not affected
Red Hat JBoss Enterprise Application Platform 6
openssl
Not affected
Red Hat JBoss Enterprise Web Server 1
openssl
Not affected
Red Hat JBoss Enterprise Web Server 2
openssl
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | openssl-0:1.0.1e-16.el6_5.14 | Fixed | RHSA-2014:0625 |
| Red Hat Enterprise Linux 7 | openssl-1:1.0.1e-34.el7_0.3 | Fixed | RHSA-2014:0679 |
| Red Hat Storage 2.1 | openssl-0:1.0.1e-16.el6_5.14 | Fixed | RHSA-2014:0628 |
| Red Hat Enterprise Linux 5 | openssl | Not affected | n/a |
| Red Hat Enterprise Linux 5 | openssl097a | Not affected | n/a |
| Red Hat Enterprise Linux 6 | guest-images | Not affected | n/a |
| Red Hat Enterprise Linux 6 | openssl098e | Not affected | n/a |
| Red Hat Enterprise Linux 7 | openssl098e | Not affected | n/a |
| Red Hat Enterprise Virtualization 3 | mingw-virt-viewer | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 5 | openssl | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | openssl | Not affected | n/a |
| Red Hat JBoss Enterprise Web Server 1 | openssl | Not affected | n/a |
| Red Hat JBoss Enterprise Web Server 2 | openssl | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue did not affect the openssl packages shipped with Red Hat Enterprise Linux 5.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (53 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 43.83% (0.43828) | 98.71th | v5 (v2026.06.15) |
| Jun 15, 2026 | 43.83% (0.43828) | 98.58th | v5 (v2026.06.15) |
| Apr 27, 2026 | 32.98% (0.32978) | 96.91th | v4 (v2025.03.14) |
| Apr 21, 2026 | 34.72% (0.34722) | 97.03th | v4 (v2025.03.14) |
| Mar 27, 2026 | 32.98% (0.32978) | 96.86th | v4 (v2025.03.14) |
| Mar 4, 2026 | 30.89% (0.30893) | 96.64th | v4 (v2025.03.14) |
| Mar 1, 2026 | 13.16% (0.13156) | 94.01th | v4 (v2025.03.14) |
| Feb 4, 2026 | 30.89% (0.30893) | 96.60th | v4 (v2025.03.14) |
| Feb 1, 2026 | 13.16% (0.13156) | 93.97th | v4 (v2025.03.14) |
| Jan 4, 2026 | 30.89% (0.30893) | 96.57th | v4 (v2025.03.14) |
| Jan 1, 2026 | 13.16% (0.13156) | 93.93th | v4 (v2025.03.14) |
| Dec 28, 2025 | 30.89% (0.30893) | 96.56th | v4 (v2025.03.14) |
| Dec 27, 2025 | 34.86% (0.34862) | 96.89th | v4 (v2025.03.14) |
| Dec 12, 2025 | 30.89% (0.30893) | 96.55th | v4 (v2025.03.14) |
| Dec 4, 2025 | 32.59% (0.32593) | 96.67th | v4 (v2025.03.14) |
| Dec 1, 2025 | 14.13% (0.14130) | 94.14th | v4 (v2025.03.14) |
| Nov 29, 2025 | 32.59% (0.32593) | 96.67th | v4 (v2025.03.14) |
| Nov 19, 2025 | 30.89% (0.30893) | 96.49th | v4 (v2025.03.14) |
| Nov 18, 2025 | 32.59% (0.32593) | 96.63th | v4 (v2025.03.14) |
| Nov 4, 2025 | 30.89% (0.30893) | 96.51th | v4 (v2025.03.14) |
| Nov 1, 2025 | 13.16% (0.13156) | 93.87th | v4 (v2025.03.14) |
| Oct 28, 2025 | 30.89% (0.30893) | 96.50th | v4 (v2025.03.14) |
| Oct 27, 2025 | 34.86% (0.34862) | 96.84th | v4 (v2025.03.14) |
| Oct 4, 2025 | 30.89% (0.30893) | 96.57th | v4 (v2025.03.14) |
| Oct 1, 2025 | 13.16% (0.13156) | 93.91th | v4 (v2025.03.14) |
| Sep 17, 2025 | 34.86% (0.34862) | 96.90th | v4 (v2025.03.14) |
| Sep 16, 2025 | 36.64% (0.36640) | 97.02th | v4 (v2025.03.14) |
| Sep 4, 2025 | 34.86% (0.34862) | 96.90th | v4 (v2025.03.14) |
| Sep 1, 2025 | 18.11% (0.18107) | 94.96th | v4 (v2025.03.14) |
| Aug 4, 2025 | 34.86% (0.34862) | 96.86th | v4 (v2025.03.14) |
| Aug 1, 2025 | 18.11% (0.18107) | 94.95th | v4 (v2025.03.14) |
| Jul 30, 2025 | 34.86% (0.34862) | 96.86th | v4 (v2025.03.14) |
| Jul 22, 2025 | 32.98% (0.32978) | 96.69th | v4 (v2025.03.14) |
| Jul 5, 2025 | 30.89% (0.30893) | 96.51th | v4 (v2025.03.14) |
| Jul 1, 2025 | 13.16% (0.13156) | 93.83th | v4 (v2025.03.14) |
| Jun 4, 2025 | 30.89% (0.30893) | 96.48th | v4 (v2025.03.14) |
| Jun 1, 2025 | 13.16% (0.13156) | 93.77th | v4 (v2025.03.14) |
| May 5, 2025 | 30.89% (0.30893) | 96.43th | v4 (v2025.03.14) |
| May 1, 2025 | 13.16% (0.13156) | 93.75th | v4 (v2025.03.14) |
| Mar 30, 2025 | 30.89% (0.30893) | 96.34th | v4 (v2025.03.14) |
| Mar 29, 2025 | 38.11% (0.38109) | 95.79th | v4 (v2025.03.14) |
| Mar 24, 2025 | 30.89% (0.30893) | 96.32th | v4 (v2025.03.14) |
| Mar 23, 2025 | 13.16% (0.13156) | 93.16th | v4 (v2025.03.14) |
| Mar 20, 2025 | 30.89% (0.30893) | 96.37th | v4 (v2025.03.14) |
| Mar 19, 2025 | 13.16% (0.13156) | 93.28th | v4 (v2025.03.14) |
| Mar 17, 2025 | 30.89% (0.30893) | 96.34th | v4 (v2025.03.14) |
| Dec 17, 2024 | 61.69% (0.61693) | 97.96th | v3 (v2023.03.01) |
| May 4, 2024 | 4.09% (0.04090) | 92.09th | v3 (v2023.03.01) |
| Dec 17, 2023 | 4.38% (0.04375) | 91.49th | v3 (v2023.03.01) |
| Oct 31, 2023 | 4.99% (0.04992) | 91.93th | v3 (v2023.03.01) |
| Mar 7, 2023 | 5.23% (0.05232) | 91.79th | v3 (v2023.03.01) |
| Mar 6, 2023 | 34.50% (0.34498) | 97.71th | v2 (v2022.01.01) |
| Feb 4, 2022 | 34.50% (0.34498) | 96.69th | v2 (v2022.01.01) |
References (116)
- http://advisories.mageia.org/MGASA-2014-0204.html x_refsource_CONFIRMThird Party Advisory
- http://aix.software.ibm.com/aix/efixes/security/openssl_advisory9.asc x_refsource_CONFIRMThird Party Advisory
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10629 x_refsource_CONFIRMThird Party Advisory
- http://kb.juniper.net/InfoCenter/index?page=content&id=KB29195 x_refsource_CONFIRMThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136470.html vendor-advisoryx_refsource_FEDORAMailing ListThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136473.html vendor-advisoryx_refsource_FEDORAMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00016.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2014-05/msg00036.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2014-05/msg00037.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=140389274407904&w=2 vendor-advisoryx_refsource_HPMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=140389355508263&w=2 vendor-advisoryx_refsource_HPMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=140431828824371&w=2 vendor-advisoryx_refsource_HPMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=140448122410568&w=2 vendor-advisoryx_refsource_HPMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=140544599631400&w=2 vendor-advisoryx_refsource_HPMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=140621259019789&w=2 vendor-advisoryx_refsource_HPMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=140752315422991&w=2 vendor-advisoryx_refsource_HPMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=140904544427729&w=2 vendor-advisoryx_refsource_HPMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=141658880509699&w=2 vendor-advisoryx_refsource_HPMailing ListThird Party Advisory
- http://puppetlabs.com/security/cve/cve-2014-0198 x_refsource_CONFIRMThird Party Advisory
- http://seclists.org/fulldisclosure/2014/Dec/23 mailing-listx_refsource_FULLDISCMailing ListThird Party Advisory
- http://secunia.com/advisories/58337 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/58667 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/58713 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/58714 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/58939 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/58945 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/58977 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59126 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59162 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59163 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59190 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59202 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59264 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59282 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59284 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59287 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59300 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59301 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59306 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59310 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59342 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59374 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59398 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59413 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59437 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59438 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59440 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59449 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59450 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59490 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59491 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59514 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59525 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59529 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59655 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59666 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59669 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59721 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59784 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59990 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/60049 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/60066 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/60571 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/61254 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://security.gentoo.org/glsa/glsa-201407-05.xml vendor-advisoryx_refsource_GENTOOThird Party Advisory
- http://support.citrix.com/article/CTX140876 x_refsource_CONFIRMThird Party Advisory
- http://support.f5.com/kb/en-us/solutions/public/15000/300/sol15329.html x_refsource_CONFIRMThird Party Advisory
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140605-openssl vendor-advisoryx_refsource_CISCOThird Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=nas8N1020163 x_refsource_CONFIRMThird Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21673137 x_refsource_CONFIRMBroken Link
- http://www-01.ibm.com/support/docview.wss?uid=swg21676035 x_refsource_CONFIRMBroken Link
- http://www-01.ibm.com/support/docview.wss?uid=swg21676062 x_refsource_CONFIRMThird Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21676419 x_refsource_CONFIRMThird Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21676529 x_refsource_CONFIRMThird Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21676655 x_refsource_CONFIRMThird Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21676879 x_refsource_CONFIRMBroken Link
- http://www-01.ibm.com/support/docview.wss?uid=swg21676889 x_refsource_CONFIRMBroken Link
- http://www-01.ibm.com/support/docview.wss?uid=swg21677527 x_refsource_CONFIRMBroken Link
- http://www-01.ibm.com/support/docview.wss?uid=swg21677695 x_refsource_CONFIRMThird Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21677828 x_refsource_CONFIRMThird Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21677836 x_refsource_CONFIRMThird Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21678167 x_refsource_CONFIRMThird Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21683332 x_refsource_CONFIRMThird Party Advisory
- http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095754 x_refsource_CONFIRMBroken Link
- http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095755 x_refsource_CONFIRMBroken Link
- http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095756 x_refsource_CONFIRMBroken Link
- http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095757 x_refsource_CONFIRMBroken Link
- http://www.blackberry.com/btsc/KB36051 x_refsource_CONFIRMThird Party Advisory
- http://www.debian.org/security/2014/dsa-2931 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- http://www.fortiguard.com/advisory/FG-IR-14-018/ x_refsource_CONFIRMThird Party Advisory
- http://www.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-345106.htm x_refsource_CONFIRMThird Party Advisory
- http://www.ibm.com/support/docview.wss?uid=swg21676356 x_refsource_CONFIRMThird Party Advisory
- http://www.ibm.com/support/docview.wss?uid=swg24037783 x_refsource_CONFIRMThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2014:080 vendor-advisoryx_refsource_MANDRIVABroken Link
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:062 vendor-advisoryx_refsource_MANDRIVABroken Link
- http://www.openbsd.org/errata55.html#005_openssl vendor-advisoryx_refsource_OPENBSDThird Party Advisory
- http://www.openssl.org/news/secadv_20140605.txt x_refsource_CONFIRMVendor Advisory
- http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html x_refsource_CONFIRMPatchThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html x_refsource_CONFIRMThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html x_refsource_CONFIRMThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html x_refsource_CONFIRMThird Party Advisory
- http://www.securityfocus.com/archive/1/534161/100/0/threaded mailing-listx_refsource_BUGTRAQThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/67193 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.vmware.com/security/advisories/VMSA-2014-0006.html x_refsource_CONFIRMThird Party Advisory
- http://www.vmware.com/security/advisories/VMSA-2014-0012.html x_refsource_CONFIRMThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2014-0198 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1093837 x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-234763.pdf x_refsource_CONFIRMThird Party Advisory
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05301946 x_refsource_CONFIRMThird Party Advisory
- https://kb.bluecoat.com/index?page=content&id=SA80 x_refsource_CONFIRMBroken Link
- https://kc.mcafee.com/corporate/index?page=content&id=SB10075 x_refsource_CONFIRMBroken Link
- https://nvd.nist.gov/vuln/detail/CVE-2014-0198
- https://rt.openssl.org/Ticket/Display.html?user=guest&pass=guest&id=3321 x_refsource_CONFIRMBroken Link
- https://www.cve.org/CVERecord?id=CVE-2014-0198
- https://www.novell.com/support/kb/doc.php?id=7015271 x_refsource_CONFIRMThird Party Advisory
- https://www.openssl.org/news/secadv_20140605.txt
Change history (0)
No recorded changes yet.