Back to search
CVE-2014-0224
Published: Jun 5, 2014
Modified: Aug 6, 2024
PUBLISHED
Description
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive information, via a crafted TLS handshake, aka the "CCS Injection" vulnerability.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
59342
third-party-advisory
x_refsource_SECUNIA
59669
third-party-advisory
x_refsource_SECUNIA
59525
third-party-advisory
x_refsource_SECUNIA
HPSBMU03071
vendor-advisory
x_refsource_HP
59004
third-party-advisory
x_refsource_SECUNIA
59530
third-party-advisory
x_refsource_SECUNIA
http://www-01.ibm.com/support/docview.wss?uid=swg21675626
x_refsource_CONFIRM
59824
third-party-advisory
x_refsource_SECUNIA
59282
third-party-advisory
x_refsource_SECUNIA
http://www.novell.com/support/kb/doc.php?id=7015300
x_refsource_CONFIRM
59215
third-party-advisory
x_refsource_SECUNIA
https://bugzilla.redhat.com/show_bug.cgi?id=1103586
x_refsource_CONFIRM
59990
third-party-advisory
x_refsource_SECUNIA
59264
third-party-advisory
x_refsource_SECUNIA
59454
third-party-advisory
x_refsource_SECUNIA
58492
third-party-advisory
x_refsource_SECUNIA
59186
third-party-advisory
x_refsource_SECUNIA
59188
third-party-advisory
x_refsource_SECUNIA
59126
third-party-advisory
x_refsource_SECUNIA
HPSBMU03078
vendor-advisory
x_refsource_HP
HPSBMU03089
vendor-advisory
x_refsource_HP
http://www.novell.com/support/kb/doc.php?id=7015264
x_refsource_CONFIRM
http://support.f5.com/kb/en-us/solutions/public/15000/300/sol15325.html
x_refsource_CONFIRM
59306
third-party-advisory
x_refsource_SECUNIA
RHSA-2014:0627
vendor-advisory
x_refsource_REDHAT
HPSBGN03068
vendor-advisory
x_refsource_HP
RHSA-2014:0626
vendor-advisory
x_refsource_REDHAT
59190
third-party-advisory
x_refsource_SECUNIA
58639
third-party-advisory
x_refsource_SECUNIA
http://www-01.ibm.com/support/docview.wss?uid=swg21678289
x_refsource_CONFIRM
http://www.ibm.com/support/docview.wss?uid=swg21676877
x_refsource_CONFIRM
59446
third-party-advisory
x_refsource_SECUNIA
59529
third-party-advisory
x_refsource_SECUNIA
59445
third-party-advisory
x_refsource_SECUNIA
http://www.vmware.com/security/advisories/VMSA-2014-0012.html
x_refsource_CONFIRM
59589
third-party-advisory
x_refsource_SECUNIA
59894
third-party-advisory
x_refsource_SECUNIA
59325
third-party-advisory
x_refsource_SECUNIA
59354
third-party-advisory
x_refsource_SECUNIA
http://www-01.ibm.com/support/docview.wss?uid=swg24037729
x_refsource_CONFIRM
http://www-01.ibm.com/support/docview.wss?uid=swg21677131
x_refsource_CONFIRM
HPSBUX03046
vendor-advisory
x_refsource_HP
61254
third-party-advisory
x_refsource_SECUNIA
http://www-01.ibm.com/support/docview.wss?uid=swg21678233
x_refsource_CONFIRM
59447
third-party-advisory
x_refsource_SECUNIA
1031594
vdb-entry
x_refsource_SECTRACK
http://www-01.ibm.com/support/docview.wss?uid=swg21676655
x_refsource_CONFIRM
59223
third-party-advisory
x_refsource_SECUNIA
58743
third-party-advisory
x_refsource_SECUNIA
http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html
x_refsource_CONFIRM
58719
third-party-advisory
x_refsource_SECUNIA
59449
third-party-advisory
x_refsource_SECUNIA
59132
third-party-advisory
x_refsource_SECUNIA
SSRT101818
vendor-advisory
x_refsource_HP
http://www-01.ibm.com/support/docview.wss?uid=isg400001843
x_refsource_CONFIRM
HPSBST03098
vendor-advisory
x_refsource_HP
HPSBMU03058
vendor-advisory
x_refsource_HP
59442
third-party-advisory
x_refsource_SECUNIA
HPSBOV03047
vendor-advisory
x_refsource_HP
HPSBST03195
vendor-advisory
x_refsource_HP
http://www-01.ibm.com/support/docview.wss?uid=swg21676879
x_refsource_CONFIRM
http://www-01.ibm.com/support/docview.wss?uid=swg24037761
x_refsource_CONFIRM
http://www-01.ibm.com/support/docview.wss?uid=swg21677828
x_refsource_CONFIRM
59441
third-party-advisory
x_refsource_SECUNIA
HPSBMU03074
vendor-advisory
x_refsource_HP
HPSBMU03094
vendor-advisory
x_refsource_HP
https://filezilla-project.org/versions.php?type=server
x_refsource_CONFIRM
http://www-01.ibm.com/support/docview.wss?uid=swg21676786
x_refsource_CONFIRM
60567
third-party-advisory
x_refsource_SECUNIA
59189
third-party-advisory
x_refsource_SECUNIA
59368
third-party-advisory
x_refsource_SECUNIA
MDVSA-2014:106
vendor-advisory
x_refsource_MANDRIVA
59142
third-party-advisory
x_refsource_SECUNIA
http://www-01.ibm.com/support/docview.wss?uid=swg21676478
x_refsource_CONFIRM
http://www-01.ibm.com/support/docview.wss?uid=swg21676845
x_refsource_CONFIRM
58742
third-party-advisory
x_refsource_SECUNIA
https://www.ibm.com/support/docview.wss?uid=ssg1S1004670
x_refsource_CONFIRM
RHSA-2014:0624
vendor-advisory
x_refsource_REDHAT
59602
third-party-advisory
x_refsource_SECUNIA
http://www.kerio.com/support/kerio-control/release-history
x_refsource_CONFIRM
59300
third-party-advisory
x_refsource_SECUNIA
58930
third-party-advisory
x_refsource_SECUNIA
http://www-01.ibm.com/support/docview.wss?uid=swg21677080
x_refsource_CONFIRM
61815
third-party-advisory
x_refsource_SECUNIA
58667
third-party-advisory
x_refsource_SECUNIA
GLSA-201407-05
vendor-advisory
x_refsource_GENTOO
http://www-01.ibm.com/support/docview.wss?uid=swg21677390
x_refsource_CONFIRM
59191
third-party-advisory
x_refsource_SECUNIA
59284
third-party-advisory
x_refsource_SECUNIA
59444
third-party-advisory
x_refsource_SECUNIA
https://www.imperialviolet.org/2014/06/05/earlyccs.html
x_refsource_MISC
http://www.ibm.com/support/docview.wss?uid=swg24037783
x_refsource_CONFIRM
59365
third-party-advisory
x_refsource_SECUNIA
http://www-01.ibm.com/support/docview.wss?uid=swg21677695
x_refsource_CONFIRM
59305
third-party-advisory
x_refsource_SECUNIA
http://www-01.ibm.com/support/docview.wss?uid=swg21676529
x_refsource_CONFIRM
59483
third-party-advisory
x_refsource_SECUNIA
58385
third-party-advisory
x_refsource_SECUNIA
20141205 NEW: VMSA-2014-0012 - VMware vSphere product updates address security vulnerabilities
mailing-list
x_refsource_BUGTRAQ
59495
third-party-advisory
x_refsource_SECUNIA
http://www-01.ibm.com/support/docview.wss?uid=nas8N1020163
x_refsource_CONFIRM
http://www-01.ibm.com/support/docview.wss?uid=swg21676889
x_refsource_CONFIRM
FEDORA-2014-9308
vendor-advisory
x_refsource_FEDORA
58945
third-party-advisory
x_refsource_SECUNIA
http://www-01.ibm.com/support/docview.wss?uid=isg400001841
x_refsource_CONFIRM
HPSBST03106
vendor-advisory
x_refsource_HP
59659
third-party-advisory
x_refsource_SECUNIA
59440
third-party-advisory
x_refsource_SECUNIA
openSUSE-SU-2016:0640
vendor-advisory
x_refsource_SUSE
59429
third-party-advisory
x_refsource_SECUNIA
http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html
x_refsource_CONFIRM
http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
x_refsource_CONFIRM
59655
third-party-advisory
x_refsource_SECUNIA
59370
third-party-advisory
x_refsource_SECUNIA
59827
third-party-advisory
x_refsource_SECUNIA
58660
third-party-advisory
x_refsource_SECUNIA
59163
third-party-advisory
x_refsource_SECUNIA
58716
third-party-advisory
x_refsource_SECUNIA
59055
third-party-advisory
x_refsource_SECUNIA
http://www-01.ibm.com/support/docview.wss?uid=swg21676071
x_refsource_CONFIRM
http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=migr-5095737
x_refsource_CONFIRM
http://www-01.ibm.com/support/docview.wss?uid=swg21677836
x_refsource_CONFIRM
59437
third-party-advisory
x_refsource_SECUNIA
http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095754
x_refsource_CONFIRM
60176
third-party-advisory
x_refsource_SECUNIA
HPSBPI03107
vendor-advisory
x_refsource_HP
59101
third-party-advisory
x_refsource_SECUNIA
http://esupport.trendmicro.com/solution/en-US/1103813.aspx
x_refsource_CONFIRM
59374
third-party-advisory
x_refsource_SECUNIA
59063
third-party-advisory
x_refsource_SECUNIA
http://www.vmware.com/security/advisories/VMSA-2014-0006.html
x_refsource_CONFIRM
https://discussions.nessus.org/thread/7517
x_refsource_CONFIRM
59310
third-party-advisory
x_refsource_SECUNIA
http://www-01.ibm.com/support/docview.wss?uid=swg21676501
x_refsource_CONFIRM
HPSBMU03216
vendor-advisory
x_refsource_HP
http://www-01.ibm.com/support/docview.wss?uid=swg21676536
x_refsource_CONFIRM
http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
x_refsource_CONFIRM
http://aix.software.ibm.com/aix/efixes/security/openssl_advisory9.asc
x_refsource_CONFIRM
IV61506
vendor-advisory
x_refsource_AIXAPAR
59502
third-party-advisory
x_refsource_SECUNIA
http://www.splunk.com/view/SP-CAAAM2D
x_refsource_CONFIRM
59878
third-party-advisory
x_refsource_SECUNIA
http://www.fortiguard.com/advisory/FG-IR-14-018/
x_refsource_CONFIRM
SUSE-SU-2015:0743
vendor-advisory
x_refsource_SUSE
HPSBMU03101
vendor-advisory
x_refsource_HP
http://www.ibm.com/support/docview.wss?uid=swg21676793
x_refsource_CONFIRM
59214
third-party-advisory
x_refsource_SECUNIA
http://www.ibm.com/support/docview.wss?uid=swg21676356
x_refsource_CONFIRM
HPSBHF03088
vendor-advisory
x_refsource_HP
HPSBMU03057
vendor-advisory
x_refsource_HP
http://support.citrix.com/article/CTX140876
x_refsource_CONFIRM
59167
third-party-advisory
x_refsource_SECUNIA
59120
third-party-advisory
x_refsource_SECUNIA
http://www-01.ibm.com/support/docview.wss?uid=swg24037732
x_refsource_CONFIRM
http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095757
x_refsource_CONFIRM
http://www-01.ibm.com/support/docview.wss?uid=nas8N1020172
x_refsource_CONFIRM
HPSBMU03053
vendor-advisory
x_refsource_HP
59380
third-party-advisory
x_refsource_SECUNIA
MDVSA-2014:105
vendor-advisory
x_refsource_MANDRIVA
59460
third-party-advisory
x_refsource_SECUNIA
59506
third-party-advisory
x_refsource_SECUNIA
58939
third-party-advisory
x_refsource_SECUNIA
SSRT101590
vendor-advisory
x_refsource_HP
59661
third-party-advisory
x_refsource_SECUNIA
59514
third-party-advisory
x_refsource_SECUNIA
59677
third-party-advisory
x_refsource_SECUNIA
RHSA-2014:0630
vendor-advisory
x_refsource_REDHAT
20140605 Multiple Vulnerabilities in OpenSSL Affecting Cisco Products
vendor-advisory
x_refsource_CISCO
http://kb.juniper.net/InfoCenter/index?page=content&id=KB29195
x_refsource_CONFIRM
RHSA-2014:0632
vendor-advisory
x_refsource_REDHAT
http://www-01.ibm.com/support/docview.wss?uid=swg24037730
x_refsource_CONFIRM
https://kc.mcafee.com/corporate/index?page=content&id=SB10075
x_refsource_CONFIRM
http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html
x_refsource_CONFIRM
http://www-01.ibm.com/support/docview.wss?uid=swg24037731
x_refsource_CONFIRM
58745
third-party-advisory
x_refsource_SECUNIA
http://www-01.ibm.com/support/docview.wss?uid=swg21676419
x_refsource_CONFIRM
59438
third-party-advisory
x_refsource_SECUNIA
http://www.ibm.com/support/docview.wss?uid=isg3T1020948
x_refsource_CONFIRM
http://www-01.ibm.com/support/docview.wss?uid=swg21676496
x_refsource_CONFIRM
58714
third-party-advisory
x_refsource_SECUNIA
HPSBGN03050
vendor-advisory
x_refsource_HP
openSUSE-SU-2015:0229
vendor-advisory
x_refsource_SUSE
http://ccsinjection.lepidum.co.jp
x_refsource_MISC
59435
third-party-advisory
x_refsource_SECUNIA
HPSBHF03052
vendor-advisory
x_refsource_HP
http://www.openssl.org/news/secadv_20140605.txt
x_refsource_CONFIRM
58615
third-party-advisory
x_refsource_SECUNIA
HPSBST03265
vendor-advisory
x_refsource_HP
20141205 NEW: VMSA-2014-0012 - VMware vSphere product updates address security vulnerabilities
mailing-list
x_refsource_FULLDISC
http://www-01.ibm.com/support/docview.wss?uid=swg21676644
x_refsource_CONFIRM
59231
third-party-advisory
x_refsource_SECUNIA
https://www.ibm.com/support/docview.wss?uid=ssg1S1004671
x_refsource_CONFIRM
SUSE-SU-2015:0578
vendor-advisory
x_refsource_SUSE
http://support.apple.com/kb/HT6443
x_refsource_CONFIRM
59211
third-party-advisory
x_refsource_SECUNIA
58433
third-party-advisory
x_refsource_SECUNIA
60066
third-party-advisory
x_refsource_SECUNIA
http://dev.mysql.com/doc/relnotes/workbench/en/wb-news-6-1-7.html
x_refsource_CONFIRM
https://access.redhat.com/site/blogs/766093/posts/908133
x_refsource_CONFIRM
59301
third-party-advisory
x_refsource_SECUNIA
60522
third-party-advisory
x_refsource_SECUNIA
59784
third-party-advisory
x_refsource_SECUNIA
https://kb.bluecoat.com/index?page=content&id=SA80
x_refsource_CONFIRM
HPSBST03097
vendor-advisory
x_refsource_HP
20140607 Re: More OpenSSL issues
mailing-list
x_refsource_FULLDISC
HPSBMU03076
vendor-advisory
x_refsource_HP
http://www.f-secure.com/en/web/labs_global/fsc-2014-6
x_refsource_CONFIRM
59135
third-party-advisory
x_refsource_SECUNIA
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10629
x_refsource_CONFIRM
http://www-01.ibm.com/support/docview.wss?uid=swg21678167
x_refsource_CONFIRM
58759
third-party-advisory
x_refsource_SECUNIA
59093
third-party-advisory
x_refsource_SECUNIA
http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095740
x_refsource_CONFIRM
http://puppetlabs.com/security/cve/cve-2014-0224
x_refsource_CONFIRM
59192
third-party-advisory
x_refsource_SECUNIA
FEDORA-2014-9301
vendor-advisory
x_refsource_FEDORA
HPSBMU03062
vendor-advisory
x_refsource_HP
58579
third-party-advisory
x_refsource_SECUNIA
59040
third-party-advisory
x_refsource_SECUNIA
HPSBMU03056
vendor-advisory
x_refsource_HP
59175
third-party-advisory
x_refsource_SECUNIA
60819
third-party-advisory
x_refsource_SECUNIA
HPSBMU03051
vendor-advisory
x_refsource_HP
59666
third-party-advisory
x_refsource_SECUNIA
58128
third-party-advisory
x_refsource_SECUNIA
HPSBMU03055
vendor-advisory
x_refsource_HP
59413
third-party-advisory
x_refsource_SECUNIA
http://www-01.ibm.com/support/docview.wss?uid=swg21676334
x_refsource_CONFIRM
http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html
x_refsource_CONFIRM
http://www-01.ibm.com/support/docview.wss?uid=swg21675821
x_refsource_CONFIRM
http://www-01.ibm.com/support/docview.wss?uid=swg24037870
x_refsource_CONFIRM
59721
third-party-advisory
x_refsource_SECUNIA
HPSBHF03145
vendor-advisory
x_refsource_HP
http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095756
x_refsource_CONFIRM
RHSA-2014:0680
vendor-advisory
x_refsource_REDHAT
http://www-01.ibm.com/support/docview.wss?uid=swg21676062
x_refsource_CONFIRM
59012
third-party-advisory
x_refsource_SECUNIA
58713
third-party-advisory
x_refsource_SECUNIA
http://www-01.ibm.com/support/docview.wss?uid=swg21673137
x_refsource_CONFIRM
59362
third-party-advisory
x_refsource_SECUNIA
MDVSA-2015:062
vendor-advisory
x_refsource_MANDRIVA
http://www-01.ibm.com/support/docview.wss?uid=swg21676035
x_refsource_CONFIRM
HPSBMU03070
vendor-advisory
x_refsource_HP
RHSA-2014:0631
vendor-advisory
x_refsource_REDHAT
59338
third-party-advisory
x_refsource_SECUNIA
59450
third-party-advisory
x_refsource_SECUNIA
http://linux.oracle.com/errata/ELSA-2014-1053.html
x_refsource_CONFIRM
http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html
x_refsource_CONFIRM
VU#978508
third-party-advisory
x_refsource_CERT-VN
1031032
vdb-entry
x_refsource_SECTRACK
59287
third-party-advisory
x_refsource_SECUNIA
http://www-01.ibm.com/support/docview.wss?uid=swg21683332
x_refsource_CONFIRM
59491
third-party-advisory
x_refsource_SECUNIA
59364
third-party-advisory
x_refsource_SECUNIA
59451
third-party-advisory
x_refsource_SECUNIA
58977
third-party-advisory
x_refsource_SECUNIA
https://www.novell.com/support/kb/doc.php?id=7015271
x_refsource_CONFIRM
http://www-01.ibm.com/support/docview.wss?uid=swg21676333
x_refsource_CONFIRM
60571
third-party-advisory
x_refsource_SECUNIA
59459
third-party-advisory
x_refsource_SECUNIA
http://www-01.ibm.com/support/docview.wss?uid=swg21676833
x_refsource_CONFIRM
60577
third-party-advisory
x_refsource_SECUNIA
59448
third-party-advisory
x_refsource_SECUNIA
http://www.blackberry.com/btsc/KB36051
x_refsource_CONFIRM
http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095755
x_refsource_CONFIRM
HPSBST03103
vendor-advisory
x_refsource_HP
http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004690
x_refsource_CONFIRM
59885
third-party-advisory
x_refsource_SECUNIA
http://www-01.ibm.com/support/docview.wss?uid=swg21677527
x_refsource_CONFIRM
59202
third-party-advisory
x_refsource_SECUNIA
RHSA-2014:0633
vendor-advisory
x_refsource_REDHAT
http://www.ibm.com/support/docview.wss?uid=ssg1S1004678
x_refsource_CONFIRM
59375
third-party-advisory
x_refsource_SECUNIA
HPSBMU03083
vendor-advisory
x_refsource_HP
59528
third-party-advisory
x_refsource_SECUNIA
58337
third-party-advisory
x_refsource_SECUNIA
59518
third-party-advisory
x_refsource_SECUNIA
59389
third-party-advisory
x_refsource_SECUNIA
59162
third-party-advisory
x_refsource_SECUNIA
59383
third-party-advisory
x_refsource_SECUNIA
http://www-01.ibm.com/support/docview.wss?uid=swg21677567
x_refsource_CONFIRM
http://kb.juniper.net/InfoCenter/index?page=content&id=KB29217
x_refsource_CONFIRM
59490
third-party-advisory
x_refsource_SECUNIA
59916
third-party-advisory
x_refsource_SECUNIA
HPSBMU03065
vendor-advisory
x_refsource_HP
http://www-01.ibm.com/support/docview.wss?uid=swg24037727
x_refsource_CONFIRM
IT02314
vendor-advisory
x_refsource_AIXAPAR
59043
third-party-advisory
x_refsource_SECUNIA
59347
third-party-advisory
x_refsource_SECUNIA
60049
third-party-advisory
x_refsource_SECUNIA
http://www-01.ibm.com/support/docview.wss?uid=swg21676615
x_refsource_CONFIRM
https://cert-portal.siemens.com/productcert/pdf/ssa-234763.pdf
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now