Vulnerability CVE-2014-3511: Information

Description

The ssl23_get_client_hello function in s23_srvr.c in OpenSSL 1.0.1 before 1.0.1i allows man-in-the-middle attackers to force the use of TLS 1.0 by triggering ClientHello message fragmentation in communication between a client and server that both support later TLS versions, related to a "protocol downgrade" issue.

Severity: MEDIUM (4.3)

Published: Aug. 14, 2014
Modified: Nov. 7, 2023

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
openssl10p91.0.1j-alt11.0.2u-alt1.p9.2ALT-PU-2014-2312-1133582Fixed
openssl10c9f21.0.1j-alt11.0.2u-alt1.p9.1ALT-PU-2014-2312-1133582Fixed
openssl10c71.0.1j-alt1.M70C.11.0.1u-alt0.M70C.1ALT-PU-2014-2316-1133754Fixed

References to Advisories, Solutions, and Tools

Hyperlink
Resource
https://www.openssl.org/news/secadv_20140806.txt
  • Vendor Advisory
http://www.arubanetworks.com/support/alerts/aid-08182014.txt
    http://www.tenable.com/security/tns-2014-06
      60810
        59887
          60377
            https://kc.mcafee.com/corporate/index?page=content&id=SB10084
              60917
                NetBSD-SA2014-008
                  http://aix.software.ibm.com/aix/efixes/security/openssl_advisory10.asc
                    60938
                      60921
                        60890
                          http://www.splunk.com/view/SP-CAAANHS
                            openSUSE-SU-2014:1052
                              DSA-2998
                                http://www.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-372998.htm
                                  61775
                                    61959
                                      http://www-01.ibm.com/support/docview.wss?uid=swg21686997
                                        http://www-01.ibm.com/support/docview.wss?uid=swg21682293
                                          59756
                                            GLSA-201412-39
                                              RHSA-2015:0197
                                                RHSA-2015:0126
                                                  SSRT101818
                                                    HPSBMU03267
                                                      SSRT101846
                                                        HPSBMU03304
                                                          https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05150888
                                                            https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05158380
                                                              HPSBMU03263
                                                                HPSBMU03261
                                                                  FreeBSD-SA-14:18
                                                                    https://techzone.ergon.ch/CVE-2014-3511
                                                                      [syslog-ng-announce] 20140910 syslog-ng Premium Edition 5 LTS (5.0.6a) has been released
                                                                        openssl-cve20143511-sec-bypass(95162)
                                                                          https://support.citrix.com/article/CTX216642
                                                                            http://linux.oracle.com/errata/ELSA-2014-1052.html
                                                                              FEDORA-2014-9301
                                                                                FEDORA-2014-9308
                                                                                  58962
                                                                                    59700
                                                                                      59710
                                                                                        60022
                                                                                          60221
                                                                                            60493
                                                                                              60684
                                                                                                60803
                                                                                                  61017
                                                                                                    61043
                                                                                                      61100
                                                                                                        61139
                                                                                                          61184
                                                                                                            http://support.f5.com/kb/en-us/solutions/public/15000/500/sol15564.html
                                                                                                              69079
                                                                                                                1030693
                                                                                                                  http://www-01.ibm.com/support/docview.wss?uid=nas8N1020240
                                                                                                                    http://www-01.ibm.com/support/docview.wss?uid=swg21683389
                                                                                                                      https://bugzilla.redhat.com/show_bug.cgi?id=1127504
                                                                                                                        HPSBMU03260
                                                                                                                          https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commit%3Bh=280b1f1ad12131defcd986676a8fc9717aaa601b
                                                                                                                              1. Configuration 1

                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.1:beta2:*:*:*:*:*:*

                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.0c:*:*:*:*:*:*:*

                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.0i:*:*:*:*:*:*:*

                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.0:beta1:*:*:*:*:*:*

                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.1h:*:*:*:*:*:*:*

                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.0:beta2:*:*:*:*:*:*

                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.0m:*:*:*:*:*:*:*

                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.1c:*:*:*:*:*:*:*

                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.1g:*:*:*:*:*:*:*

                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.0h:*:*:*:*:*:*:*

                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.0:beta3:*:*:*:*:*:*

                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.0e:*:*:*:*:*:*:*

                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.1:beta3:*:*:*:*:*:*

                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.0f:*:*:*:*:*:*:*

                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.0d:*:*:*:*:*:*:*

                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.0j:*:*:*:*:*:*:*

                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.1a:*:*:*:*:*:*:*

                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.1:beta1:*:*:*:*:*:*

                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.1d:*:*:*:*:*:*:*

                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.0k:*:*:*:*:*:*:*

                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.0:beta4:*:*:*:*:*:*

                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.0:*:*:*:*:*:*:*

                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.1b:*:*:*:*:*:*:*

                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.1e:*:*:*:*:*:*:*

                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.0:beta5:*:*:*:*:*:*

                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.1f:*:*:*:*:*:*:*

                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.0l:*:*:*:*:*:*:*

                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.0a:*:*:*:*:*:*:*

                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.0b:*:*:*:*:*:*:*

                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.1:*:*:*:*:*:*:*

                                                                                                                                cpe:2.3:a:openssl:openssl:1.0.0g:*:*:*:*:*:*:*