openssl: crash with SRP ciphersuite in Server Hello message
Published Aug 13, 2014
4.3
MEDIUMCVSS 2.0
EPSS 16.29%
Description
The ssl_set_client_disabled function in t1_lib.c in OpenSSL 1.0.1 before 1.0.1i allows remote SSL servers to cause a denial of service (NULL pointer dereference and client application crash) via a ServerHello message that includes an SRP ciphersuite without the required negotiation of that ciphersuite with the client.
Affected products
No data.
- 1.0.1
- 1.0.1
- 1.0.1
- 1.0.1
- 1.0.1a
- 1.0.1b
- 1.0.1c
- 1.0.1d
- 1.0.1e
- 1.0.1f
- 1.0.1g
- 1.0.1h
No data.
Red Hat Enterprise Linux 5
openssl
Not affected
Red Hat Enterprise Linux 5
openssl097a
Not affected
Red Hat Enterprise Linux 6
openssl
Not affected
Red Hat Enterprise Linux 6
openssl098e
Not affected
Red Hat Enterprise Linux 7
openssl
Not affected
Red Hat Enterprise Linux 7
openssl098e
Not affected
Red Hat Enterprise Virtualization 3
mingw-virt-viewer
Not affected
Red Hat Enterprise Virtualization 3
rhev-hypervisor
Not affected
Red Hat JBoss Enterprise Application Platform 5
openssl
Not affected
Red Hat JBoss Enterprise Application Platform 6
openssl
Not affected
Red Hat JBoss Enterprise Web Server 1
openssl
Not affected
Red Hat JBoss Enterprise Web Server 2
openssl
Not affected
Red Hat Storage 2
openssl
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | openssl | Not affected | n/a |
| Red Hat Enterprise Linux 5 | openssl097a | Not affected | n/a |
| Red Hat Enterprise Linux 6 | openssl | Not affected | n/a |
| Red Hat Enterprise Linux 6 | openssl098e | Not affected | n/a |
| Red Hat Enterprise Linux 7 | openssl | Not affected | n/a |
| Red Hat Enterprise Linux 7 | openssl098e | Not affected | n/a |
| Red Hat Enterprise Virtualization 3 | mingw-virt-viewer | Not affected | n/a |
| Red Hat Enterprise Virtualization 3 | rhev-hypervisor | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 5 | openssl | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | openssl | Not affected | n/a |
| Red Hat JBoss Enterprise Web Server 1 | openssl | Not affected | n/a |
| Red Hat JBoss Enterprise Web Server 2 | openssl | Not affected | n/a |
| Red Hat Storage 2 | openssl | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Not vulnerable. This issue did not affect the versions of openssl as shipped with Red Hat Enterprise Linux 5, 6 and 7, Red Hat Enterprise Virtualization 3, and Red Hat Enterprise Storage 2, as they do not enable Secure Remote Password (SRP) support. All other supported Red Hat products that include openssl use older versions that are not affected by this issue.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (55 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 16.29% (0.16290) | 96.86th | v5 (v2026.06.15) |
| Aug 22, 2026 | 16.22% (0.16219) | 96.69th | v5 (v2026.06.15) |
| Jun 15, 2026 | 19.55% (0.19546) | 97.03th | v5 (v2026.06.15) |
| May 13, 2026 | 34.03% (0.34029) | 97.02th | v4 (v2025.03.14) |
| Apr 15, 2026 | 41.16% (0.41157) | 97.39th | v4 (v2025.03.14) |
| Mar 4, 2026 | 21.08% (0.21083) | 95.54th | v4 (v2025.03.14) |
| Mar 1, 2026 | 8.21% (0.08213) | 92.09th | v4 (v2025.03.14) |
| Feb 4, 2026 | 21.08% (0.21083) | 95.50th | v4 (v2025.03.14) |
| Feb 1, 2026 | 8.21% (0.08213) | 92.03th | v4 (v2025.03.14) |
| Jan 4, 2026 | 21.08% (0.21083) | 95.46th | v4 (v2025.03.14) |
| Jan 1, 2026 | 8.21% (0.08213) | 91.98th | v4 (v2025.03.14) |
| Dec 28, 2025 | 21.08% (0.21083) | 95.46th | v4 (v2025.03.14) |
| Dec 27, 2025 | 15.22% (0.15223) | 94.42th | v4 (v2025.03.14) |
| Dec 4, 2025 | 21.08% (0.21083) | 95.43th | v4 (v2025.03.14) |
| Dec 1, 2025 | 8.21% (0.08213) | 91.91th | v4 (v2025.03.14) |
| Nov 4, 2025 | 21.31% (0.21313) | 95.45th | v4 (v2025.03.14) |
| Nov 1, 2025 | 7.86% (0.07856) | 91.64th | v4 (v2025.03.14) |
| Oct 28, 2025 | 21.31% (0.21313) | 95.43th | v4 (v2025.03.14) |
| Oct 27, 2025 | 15.40% (0.15405) | 94.36th | v4 (v2025.03.14) |
| Oct 4, 2025 | 21.31% (0.21313) | 95.49th | v4 (v2025.03.14) |
| Oct 1, 2025 | 7.86% (0.07856) | 91.69th | v4 (v2025.03.14) |
| Sep 5, 2025 | 15.40% (0.15405) | 94.40th | v4 (v2025.03.14) |
| Sep 1, 2025 | 4.39% (0.04387) | 88.63th | v4 (v2025.03.14) |
| Aug 4, 2025 | 15.40% (0.15405) | 94.35th | v4 (v2025.03.14) |
| Aug 1, 2025 | 4.39% (0.04387) | 88.63th | v4 (v2025.03.14) |
| Jul 30, 2025 | 15.40% (0.15405) | 94.35th | v4 (v2025.03.14) |
| Jul 4, 2025 | 21.31% (0.21313) | 95.40th | v4 (v2025.03.14) |
| Jul 1, 2025 | 7.86% (0.07856) | 91.60th | v4 (v2025.03.14) |
| Jun 4, 2025 | 21.31% (0.21313) | 95.36th | v4 (v2025.03.14) |
| Jun 1, 2025 | 7.86% (0.07856) | 91.57th | v4 (v2025.03.14) |
| May 5, 2025 | 21.31% (0.21313) | 95.30th | v4 (v2025.03.14) |
| May 1, 2025 | 7.86% (0.07856) | 91.56th | v4 (v2025.03.14) |
| Apr 20, 2025 | 21.31% (0.21313) | 95.29th | v4 (v2025.03.14) |
| Apr 19, 2025 | 7.86% (0.07856) | 91.51th | v4 (v2025.03.14) |
| Apr 15, 2025 | 21.31% (0.21313) | 95.27th | v4 (v2025.03.14) |
| Apr 13, 2025 | 7.86% (0.07856) | 91.23th | v4 (v2025.03.14) |
| Mar 30, 2025 | 21.31% (0.21313) | 95.20th | v4 (v2025.03.14) |
| Mar 29, 2025 | 26.38% (0.26377) | 94.07th | v4 (v2025.03.14) |
| Mar 28, 2025 | 21.31% (0.21313) | 95.20th | v4 (v2025.03.14) |
| Mar 27, 2025 | 26.38% (0.26377) | 95.58th | v4 (v2025.03.14) |
| Mar 21, 2025 | 21.31% (0.21313) | 95.22th | v4 (v2025.03.14) |
| Mar 20, 2025 | 7.86% (0.07856) | 91.30th | v4 (v2025.03.14) |
| Mar 19, 2025 | 26.38% (0.26377) | 95.67th | v4 (v2025.03.14) |
| Mar 17, 2025 | 21.31% (0.21313) | 95.21th | v4 (v2025.03.14) |
| Dec 12, 2024 | 4.96% (0.04958) | 93.12th | v3 (v2023.03.01) |
| Mar 25, 2024 | 4.96% (0.04958) | 92.64th | v3 (v2023.03.01) |
| Feb 7, 2024 | 4.63% (0.04629) | 91.76th | v3 (v2023.03.01) |
| Nov 8, 2023 | 5.46% (0.05459) | 92.35th | v3 (v2023.03.01) |
| Oct 28, 2023 | 2.01% (0.02011) | 87.63th | v3 (v2023.03.01) |
| Sep 7, 2023 | 2.46% (0.02465) | 88.70th | v3 (v2023.03.01) |
| Apr 20, 2023 | 2.21% (0.02210) | 87.79th | v3 (v2023.03.01) |
| Mar 7, 2023 | 2.55% (0.02554) | 88.53th | v3 (v2023.03.01) |
| Mar 6, 2023 | 4.72% (0.04720) | 89.23th | v2 (v2022.01.01) |
| Apr 1, 2022 | 4.72% (0.04720) | 88.14th | v2 (v2022.01.01) |
| Feb 4, 2022 | 4.72% (0.04720) | 74.52th | v2 (v2022.01.01) |
References (51)
- ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2014-008.txt.asc vendor-advisoryx_refsource_NETBSD
- http://aix.software.ibm.com/aix/efixes/security/openssl_advisory10.asc x_refsource_CONFIRM
- http://lists.opensuse.org/opensuse-updates/2014-08/msg00036.html vendor-advisoryx_refsource_SUSE
- http://marc.info/?l=bugtraq&m=142350350616251&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=142495837901899&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=142624590206005&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=142624619906067 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=142624619906067&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=142624679706236&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=142624719706349&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=142660345230545&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=142791032306609&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=143290437727362&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=143290522027658&w=2 vendor-advisoryx_refsource_HP
- http://secunia.com/advisories/59700 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/59710 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/59756 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/60022 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/60221 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/60493 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/60803 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/60810 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/60917 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/60921 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61017 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61100 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61171 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61184 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61392 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61775 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61959 third-party-advisoryx_refsource_SECUNIA
- http://security.gentoo.org/glsa/glsa-201412-39.xml vendor-advisoryx_refsource_GENTOO
- http://support.f5.com/kb/en-us/solutions/public/15000/500/sol15567.html x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=nas8N1020240 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21682293 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21683389 x_refsource_CONFIRM
- http://www-01.ibm.com/support/docview.wss?uid=swg21686997 x_refsource_CONFIRM
- http://www.debian.org/security/2014/dsa-2998 vendor-advisoryx_refsource_DEBIAN
- http://www.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-372998.htm x_refsource_CONFIRM
- http://www.securityfocus.com/bid/69077 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id/1030693 vdb-entryx_refsource_SECTRACK
- http://www.tenable.com/security/tns-2014-06 x_refsource_CONFIRM
- https://access.redhat.com/security/cve/CVE-2014-5139 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1127491 Issue Tracking
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commit%3Bh=80bd7b41b30af6ee96f519e629463583318de3b0 x_refsource_CONFIRM
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commit%3Bh=83764a989dcc87fbea337da5f8f86806fe767b7e x_refsource_CONFIRM
- https://lists.balabit.hu/pipermail/syslog-ng-announce/2014-September/000196.html mailing-listx_refsource_MLIST
- https://nvd.nist.gov/vuln/detail/CVE-2014-5139
- https://www.cve.org/CVERecord?id=CVE-2014-5139
- https://www.freebsd.org/security/advisories/FreeBSD-SA-14:18.openssl.asc vendor-advisoryx_refsource_FREEBSD
- https://www.openssl.org/news/secadv_20140806.txt x_refsource_CONFIRMVendor Advisory
Change history (0)
No recorded changes yet.