CVE-2014-3566
low · 3.4The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.
3.4
CVSS
100.0%
EPSS (exploit prob.)
100th
EPSS percentile
2014-10-15
Published
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N
Weaknesses
CWE-310CWE-329
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| redhat | enterprise_linux | 5 |
| redhat | enterprise_linux_desktop | 6.0 |
| redhat | enterprise_linux_desktop | 7.0 |
| redhat | enterprise_linux_desktop_supplementary | 5.0 |
| redhat | enterprise_linux_desktop_supplementary | 6.0 |
| redhat | enterprise_linux_server | 6.0 |
| redhat | enterprise_linux_server | 7.0 |
| redhat | enterprise_linux_server_supplementary | 5.0 |
| redhat | enterprise_linux_server_supplementary | 6.0 |
| redhat | enterprise_linux_server_supplementary | 7.0 |
| redhat | enterprise_linux_workstation | 6.0 |
| redhat | enterprise_linux_workstation | 7.0 |
| redhat | enterprise_linux_workstation_supplementary | 6.0 |
| redhat | enterprise_linux_workstation_supplementary | 7.0 |
| ibm | aix | 5.3 |
| ibm | aix | 6.1 |
| ibm | aix | 7.1 |
| apple | mac_os_x | <= 10.10.1 |
| mageia | mageia | 3.0 |
| mageia | mageia | 4.0 |
| novell | suse_linux_enterprise_desktop | 9.0 |
| novell | suse_linux_enterprise_desktop | 10.0 |
| novell | suse_linux_enterprise_desktop | 11.0 |
| novell | suse_linux_enterprise_desktop | 12.0 |
| novell | suse_linux_enterprise_software_development_kit | 11.0 |
| novell | suse_linux_enterprise_software_development_kit | 12.0 |
| novell | suse_linux_enterprise_server | 11.0 |
| novell | suse_linux_enterprise_server | 11.0 |
| novell | suse_linux_enterprise_server | 12.0 |
| opensuse | opensuse | 12.3 |
| opensuse | opensuse | 13.1 |
| fedoraproject | fedora | 19 |
| fedoraproject | fedora | 20 |
| fedoraproject | fedora | 21 |
| openssl | openssl | 0.9.8 |
| openssl | openssl | 0.9.8a |
| openssl | openssl | 0.9.8b |
| openssl | openssl | 0.9.8c |
| openssl | openssl | 0.9.8d |
| openssl | openssl | 0.9.8e |
Check a specific version with /api/v1/cve/match.
References
- ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2014-015.txt.asc
- http://advisories.mageia.org/MGASA-2014-0416.html
- http://aix.software.ibm.com/aix/efixes/security/openssl_advisory11.asc
- http://archives.neohapsis.com/archives/bugtraq/2014-10/0101.html
- http://archives.neohapsis.com/archives/bugtraq/2014-10/0103.html
- http://askubuntu.com/questions/537196/how-do-i-patch-workaround-sslv3-poodle-vulnerability-cve-2014-3566
- http://blog.cryptographyengineering.com/2014/10/attack-of-week-poodle.html
- http://blog.nodejs.org/2014/10/23/node-v0-10-33-stable/
- http://blogs.technet.com/b/msrc/archive/2014/10/14/security-advisory-3009008-released.aspx
- http://docs.ipswitch.com/MOVEit/DMZ82/ReleaseNotes/MOVEitReleaseNotes82.pdf
- http://downloads.asterisk.org/pub/security/AST-2014-011.html
- http://googleonlinesecurity.blogspot.com/2014/10/this-poodle-bites-exploiting-ssl-30.html
- http://h20564.www2.hp.com/hpsc/doc/public/display?docId=emr_na-c04583581
- http://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c04779034
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705
- http://lists.apple.com/archives/security-announce/2015/Jan/msg00003.html
- http://lists.apple.com/archives/security-announce/2015/Sep/msg00002.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-November/142330.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-October/141114.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-October/141158.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-October/169361.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-October/169374.html
- http://lists.opensuse.org/opensuse-security-announce/2014-10/msg00008.html
- http://lists.opensuse.org/opensuse-security-announce/2014-11/msg00001.html
- http://lists.opensuse.org/opensuse-security-announce/2014-11/msg00003.html
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2014-3566