openssl: denial of service in ssl23_get_client_hello function
Published Dec 24, 2014
5.0
MEDIUMCVSS 2.0
EPSS 19.52%
Description
The ssl23_get_client_hello function in s23_srvr.c in OpenSSL 0.9.8zc, 1.0.0o, and 1.0.1j does not properly handle attempts to use unsupported protocols, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an unexpected handshake, as demonstrated by an SSLv3 handshake to a no-ssl3 application with certain error handling. NOTE: this issue became relevant after the CVE-2014-3568 fix.
Affected products
No data.
No data.
Red Hat Enterprise Linux 5
openssl
Not affected
Red Hat Enterprise Linux 6
openssl
Not affected
Red Hat Enterprise Linux 7
openssl
Not affected
Red Hat JBoss Enterprise Application Platform 5
openssl
Not affected
Red Hat JBoss Enterprise Application Platform 6
openssl
Not affected
Red Hat JBoss Enterprise Web Server 1
openssl
Not affected
Red Hat JBoss Enterprise Web Server 2
openssl
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | openssl | Not affected | n/a |
| Red Hat Enterprise Linux 6 | openssl | Not affected | n/a |
| Red Hat Enterprise Linux 7 | openssl | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 5 | openssl | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | openssl | Not affected | n/a |
| Red Hat JBoss Enterprise Web Server 1 | openssl | Not affected | n/a |
| Red Hat JBoss Enterprise Web Server 2 | openssl | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Not vulnerable. The versions of openssl package as shipped in Red Hat Enterprise Linux 5, 6 and 7; Red Hat JBoss Enterprise Application Platform 5 and 6; and Red Hat JBoss Enterprise Web Server 1 and 2 are not vulnerable to CVE-2014-3568, therefore does not have CVE-2014-3568 fix applied, and therefore are not vulnerable to this security flaw.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (31 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 19.52% (0.19524) | 97.30th | v5 (v2026.06.15) |
| Aug 5, 2026 | 19.52% (0.19524) | 97.11th | v5 (v2026.06.15) |
| Jun 15, 2026 | 20.65% (0.20646) | 97.19th | v5 (v2026.06.15) |
| Mar 22, 2026 | 7.45% (0.07448) | 91.68th | v4 (v2025.03.14) |
| Feb 19, 2026 | 8.59% (0.08593) | 92.23th | v4 (v2025.03.14) |
| Dec 28, 2025 | 11.39% (0.11389) | 93.33th | v4 (v2025.03.14) |
| Dec 27, 2025 | 7.66% (0.07659) | 91.62th | v4 (v2025.03.14) |
| Dec 21, 2025 | 11.39% (0.11389) | 93.31th | v4 (v2025.03.14) |
| Dec 7, 2025 | 8.59% (0.08593) | 92.08th | v4 (v2025.03.14) |
| Oct 28, 2025 | 14.26% (0.14259) | 94.09th | v4 (v2025.03.14) |
| Oct 27, 2025 | 9.72% (0.09719) | 92.60th | v4 (v2025.03.14) |
| Oct 1, 2025 | 14.26% (0.14259) | 94.19th | v4 (v2025.03.14) |
| Jul 30, 2025 | 9.72% (0.09719) | 92.60th | v4 (v2025.03.14) |
| Apr 12, 2025 | 14.26% (0.14259) | 93.82th | v4 (v2025.03.14) |
| Apr 10, 2025 | 12.32% (0.12318) | 93.28th | v4 (v2025.03.14) |
| Apr 1, 2025 | 9.78% (0.09783) | 92.23th | v4 (v2025.03.14) |
| Mar 30, 2025 | 12.36% (0.12356) | 93.27th | v4 (v2025.03.14) |
| Mar 29, 2025 | 19.71% (0.19708) | 92.54th | v4 (v2025.03.14) |
| Mar 17, 2025 | 12.36% (0.12356) | 93.33th | v4 (v2025.03.14) |
| Dec 22, 2024 | 78.29% (0.78289) | 98.47th | v3 (v2023.03.01) |
| Nov 5, 2024 | 85.57% (0.85568) | 98.63th | v3 (v2023.03.01) |
| Aug 5, 2024 | 88.14% (0.88138) | 98.72th | v3 (v2023.03.01) |
| Jun 19, 2024 | 89.15% (0.89153) | 98.75th | v3 (v2023.03.01) |
| Mar 9, 2024 | 89.11% (0.89114) | 98.65th | v3 (v2023.03.01) |
| Aug 31, 2023 | 90.25% (0.90248) | 98.39th | v3 (v2023.03.01) |
| Jun 8, 2023 | 90.96% (0.90959) | 98.36th | v3 (v2023.03.01) |
| Apr 29, 2023 | 92.36% (0.92361) | 98.44th | v3 (v2023.03.01) |
| Mar 7, 2023 | 92.99% (0.92986) | 98.44th | v3 (v2023.03.01) |
| Mar 6, 2023 | 7.56% (0.07559) | 92.87th | v2 (v2022.01.01) |
| Apr 1, 2022 | 7.56% (0.07559) | 92.17th | v2 (v2022.01.01) |
| Feb 4, 2022 | 7.56% (0.07559) | 81.11th | v2 (v2022.01.01) |
References (44)
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10679 x_refsource_CONFIRM
- http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.html vendor-advisoryx_refsource_APPLE
- http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00021.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00026.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.html vendor-advisoryx_refsource_SUSE
- http://marc.info/?l=bugtraq&m=142496179803395&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=142496289803847&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=142721102728110&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=142895206924048&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=143748090628601&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=144050155601375&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=144050205101530&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=144050254401665&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=144050297101809&w=2 vendor-advisoryx_refsource_HP
- http://people.canonical.com/~ubuntu-security/cve/2014/CVE-2014-3569.html x_refsource_CONFIRM
- http://rt.openssl.org/Ticket/Display.html?id=3571&user=guest&pass=guest x_refsource_CONFIRM
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150310-ssl vendor-advisoryx_refsource_CISCO
- http://www.debian.org/security/2015/dsa-3125 vendor-advisoryx_refsource_DEBIAN
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:019 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:062 vendor-advisoryx_refsource_MANDRIVA
- http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html x_refsource_CONFIRM
- http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html x_refsource_CONFIRM
- http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html x_refsource_CONFIRM
- http://www.oracle.com/technetwork/topics/security/cpuapr2015-2365600.html x_refsource_CONFIRM
- http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html x_refsource_CONFIRM
- http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html x_refsource_CONFIRM
- http://www.securityfocus.com/bid/71934 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id/1033378 vdb-entryx_refsource_SECTRACK
- https://access.redhat.com/security/cve/CVE-2014-3569 Vendor Advisory
- https://bto.bluecoat.com/security-advisory/sa88 x_refsource_CONFIRM
- https://bugzilla.redhat.com/show_bug.cgi?id=1177249 Issue Tracking
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commit%3Bh=392fa7a952e97d82eac6958c81ed1e256e6b8ca5 x_refsource_CONFIRM
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commit%3Bh=6ce9687b5aba5391fc0de50e18779eb676d0e04d x_refsource_CONFIRM
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commit%3Bh=b82924741b4bd590da890619be671f4635e46c2b x_refsource_CONFIRM
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05150888 x_refsource_CONFIRM
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05158380 x_refsource_CONFIRM
- https://kc.mcafee.com/corporate/index?page=content&id=SB10102 x_refsource_CONFIRM
- https://kc.mcafee.com/corporate/index?page=content&id=SB10108 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2014-3569
- https://security-tracker.debian.org/tracker/CVE-2014-3569 x_refsource_CONFIRM
- https://support.apple.com/HT204659 x_refsource_CONFIRM
- https://support.citrix.com/article/CTX216642 x_refsource_CONFIRM
- https://www.cve.org/CVERecord?id=CVE-2014-3569
- https://www.openssl.org/news/secadv_20150108.txt x_refsource_CONFIRM
Change history (0)
No recorded changes yet.