CVE-2014-0221

OpenSSL <0.9.8za, <1.0.0m, <1.0.1h - DoS

Title source: llm

Description

The dtls1_get_message_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h allows remote attackers to cause a denial of service (recursion and client crash) via a DTLS hello message in an invalid DTLS handshake.

Exploits (1)

nomisec WRITEUP
by tpdlshdmlrkfmcla · poc
https://github.com/tpdlshdmlrkfmcla/OpenSSL_DTLS_CVE_2014_0221

References (127)

... and 107 more

Scores

EPSS 0.8210
EPSS Percentile 99.2%

Details

Status published
Products (14)
fedoraproject/fedora
fedoraproject/fedora 19
fedoraproject/fedora 20
mariadb/mariadb 10.0.0 - 10.0.13
openssl/openssl 0.9.8 - 0.9.8za
opensuse/leap 42.1
opensuse/opensuse 13.2
redhat/enterprise_linux 5
redhat/enterprise_linux 6.0
redhat/storage 2.1
... and 4 more
Published Jun 05, 2014
Tracked Since Feb 18, 2026