CVE-2014-8275
medium · 5OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k does not enforce certain constraints on certificate data, which allows remote attackers to defeat a fingerprint-based certificate-blacklist protection mechanism by including crafted data within a certificate's unsigned portion, related to crypto/asn1/a_verify.c, crypto/dsa/dsa_asn1.c, crypto/ecdsa/ecs_vrf.c, and crypto/x509/x_all.c.
5
CVSS
15.8%
EPSS (exploit prob.)
97th
EPSS percentile
2015-01-09
Published
AV:N/AC:L/Au:N/C:N/I:P/A:N
Weaknesses
CWE-310
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| openssl | openssl | <= 0.9.8zc |
| openssl | openssl | 1.0.0a |
| openssl | openssl | 1.0.0b |
| openssl | openssl | 1.0.0c |
| openssl | openssl | 1.0.0d |
| openssl | openssl | 1.0.0e |
| openssl | openssl | 1.0.0f |
| openssl | openssl | 1.0.0g |
| openssl | openssl | 1.0.0h |
| openssl | openssl | 1.0.0i |
| openssl | openssl | 1.0.0j |
| openssl | openssl | 1.0.0k |
| openssl | openssl | 1.0.0l |
| openssl | openssl | 1.0.0m |
| openssl | openssl | 1.0.0n |
| openssl | openssl | 1.0.0o |
| openssl | openssl | 1.0.1a |
| openssl | openssl | 1.0.1b |
| openssl | openssl | 1.0.1c |
| openssl | openssl | 1.0.1d |
| openssl | openssl | 1.0.1e |
| openssl | openssl | 1.0.1f |
| openssl | openssl | 1.0.1g |
| openssl | openssl | 1.0.1h |
| openssl | openssl | 1.0.1i |
| openssl | openssl | 1.0.1j |
Check a specific version with /api/v1/cve/match.
References
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10679
- http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-January/148363.html
- http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00021.html
- http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00027.html
- http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00026.html
- http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00037.html
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.html
- http://marc.info/?l=bugtraq&m=142496179803395&w=2
- http://marc.info/?l=bugtraq&m=142496289803847&w=2
- http://marc.info/?l=bugtraq&m=142720981827617&w=2
- http://marc.info/?l=bugtraq&m=142721102728110&w=2
- http://marc.info/?l=bugtraq&m=142895206924048&w=2
- http://marc.info/?l=bugtraq&m=143748090628601&w=2
- http://marc.info/?l=bugtraq&m=144050155601375&w=2
- http://marc.info/?l=bugtraq&m=144050205101530&w=2
- http://marc.info/?l=bugtraq&m=144050254401665&w=2
- http://marc.info/?l=bugtraq&m=144050297101809&w=2
- http://rhn.redhat.com/errata/RHSA-2015-0066.html
- http://rhn.redhat.com/errata/RHSA-2015-0800.html
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150310-ssl
- http://www.debian.org/security/2015/dsa-3125
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:019
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:062
- http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2014-8275