Back to search
CVE-2014-5139
Published: Aug 13, 2014
Modified: Aug 6, 2024
PUBLISHED
Description
The ssl_set_client_disabled function in t1_lib.c in OpenSSL 1.0.1 before 1.0.1i allows remote SSL servers to cause a denial of service (NULL pointer dereference and client application crash) via a ServerHello message that includes an SRP ciphersuite without the required negotiation of that ciphersuite with the client.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
openSUSE-SU-2014:1052
vendor-advisory
x_refsource_SUSE
http://support.f5.com/kb/en-us/solutions/public/15000/500/sol15567.html
x_refsource_CONFIRM
60221
third-party-advisory
x_refsource_SECUNIA
http://www-01.ibm.com/support/docview.wss?uid=swg21682293
x_refsource_CONFIRM
61184
third-party-advisory
x_refsource_SECUNIA
SSRT101846
vendor-advisory
x_refsource_HP
60022
third-party-advisory
x_refsource_SECUNIA
https://www.openssl.org/news/secadv_20140806.txt
x_refsource_CONFIRM
61017
third-party-advisory
x_refsource_SECUNIA
SSRT101818
vendor-advisory
x_refsource_HP
http://www-01.ibm.com/support/docview.wss?uid=swg21683389
x_refsource_CONFIRM
HPSBMU03304
vendor-advisory
x_refsource_HP
HPSBMU03259
vendor-advisory
x_refsource_HP
GLSA-201412-39
vendor-advisory
x_refsource_GENTOO
HPSBHF03293
vendor-advisory
x_refsource_HP
69077
vdb-entry
x_refsource_BID
HPSBMU03260
vendor-advisory
x_refsource_HP
60803
third-party-advisory
x_refsource_SECUNIA
59700
third-party-advisory
x_refsource_SECUNIA
1030693
vdb-entry
x_refsource_SECTRACK
60917
third-party-advisory
x_refsource_SECUNIA
HPSBMU03216
vendor-advisory
x_refsource_HP
http://www.tenable.com/security/tns-2014-06
x_refsource_CONFIRM
60493
third-party-advisory
x_refsource_SECUNIA
59710
third-party-advisory
x_refsource_SECUNIA
60921
third-party-advisory
x_refsource_SECUNIA
60810
third-party-advisory
x_refsource_SECUNIA
HPSBMU03283
vendor-advisory
x_refsource_HP
http://www-01.ibm.com/support/docview.wss?uid=nas8N1020240
x_refsource_CONFIRM
61100
third-party-advisory
x_refsource_SECUNIA
FreeBSD-SA-14:18
vendor-advisory
x_refsource_FREEBSD
61775
third-party-advisory
x_refsource_SECUNIA
SSRT101894
vendor-advisory
x_refsource_HP
DSA-2998
vendor-advisory
x_refsource_DEBIAN
HPSBMU03263
vendor-advisory
x_refsource_HP
SSRT101921
vendor-advisory
x_refsource_HP
61959
third-party-advisory
x_refsource_SECUNIA
59756
third-party-advisory
x_refsource_SECUNIA
HPSBMU03262
vendor-advisory
x_refsource_HP
HPSBMU03267
vendor-advisory
x_refsource_HP
HPSBMU03261
vendor-advisory
x_refsource_HP
http://aix.software.ibm.com/aix/efixes/security/openssl_advisory10.asc
x_refsource_CONFIRM
61392
third-party-advisory
x_refsource_SECUNIA
SSRT101916
vendor-advisory
x_refsource_HP
[syslog-ng-announce] 20140910 syslog-ng Premium Edition 5 LTS (5.0.6a) has been released
mailing-list
x_refsource_MLIST
61171
third-party-advisory
x_refsource_SECUNIA
SSRT101922
vendor-advisory
x_refsource_HP
http://www-01.ibm.com/support/docview.wss?uid=swg21686997
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now