Vulnerability CVE-2014-5139: Information

Description

The ssl_set_client_disabled function in t1_lib.c in OpenSSL 1.0.1 before 1.0.1i allows remote SSL servers to cause a denial of service (NULL pointer dereference and client application crash) via a ServerHello message that includes an SRP ciphersuite without the required negotiation of that ciphersuite with the client.

Severity: MEDIUM (4.3)

Published: Aug. 14, 2014
Modified: Nov. 7, 2023

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
openssl10p91.0.1j-alt11.0.2u-alt1.p9.2ALT-PU-2014-2312-1133582Fixed
openssl10c9f21.0.1j-alt11.0.2u-alt1.p9.1ALT-PU-2014-2312-1133582Fixed
openssl10c71.0.1j-alt1.M70C.11.0.1u-alt0.M70C.1ALT-PU-2014-2316-1133754Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:openssl:openssl:1.0.1:beta2:*:*:*:*:*:*

      cpe:2.3:a:openssl:openssl:1.0.1h:*:*:*:*:*:*:*

      cpe:2.3:a:openssl:openssl:1.0.1c:*:*:*:*:*:*:*

      cpe:2.3:a:openssl:openssl:1.0.1g:*:*:*:*:*:*:*

      cpe:2.3:a:openssl:openssl:1.0.1:beta3:*:*:*:*:*:*

      cpe:2.3:a:openssl:openssl:1.0.1a:*:*:*:*:*:*:*

      cpe:2.3:a:openssl:openssl:1.0.1:beta1:*:*:*:*:*:*

      cpe:2.3:a:openssl:openssl:1.0.1d:*:*:*:*:*:*:*

      cpe:2.3:a:openssl:openssl:1.0.1b:*:*:*:*:*:*:*

      cpe:2.3:a:openssl:openssl:1.0.1e:*:*:*:*:*:*:*

      cpe:2.3:a:openssl:openssl:1.0.1f:*:*:*:*:*:*:*

      cpe:2.3:a:openssl:openssl:1.0.1:*:*:*:*:*:*:*