Vulnerability Note VU#978508
OpenSSL is vulnerable to a man-in-the-middle attack
Overview
OpenSSL is vulnerable to a man-in-the-middle attack.
Description
The OpenSSL security advisory states: SSL/TLS MITM vulnerability (CVE-2014-0224) Masashi Kikuchi has written a technical blog post about the vulnerability. |
Impact
A remote attacker with a man-in-the-middle vantage point on the network may be able to decrypt or modify traffic between a client and server. |
Solution
Apply an Update |
Vendor Information (Learn More)
Vendor | Status | Date Notified | Date Updated |
---|---|---|---|
FreeBSD Project | Affected | 02 Jun 2014 | 05 Jun 2014 |
OpenSSL | Affected | 09 May 2014 | 05 Jun 2014 |
Red Hat, Inc. | Affected | 02 Jun 2014 | 05 Jun 2014 |
Ubuntu | Affected | 02 Jun 2014 | 05 Jun 2014 |
ACCESS | Unknown | 02 Jun 2014 | 02 Jun 2014 |
Alcatel-Lucent | Unknown | 02 Jun 2014 | 02 Jun 2014 |
Apple Inc. | Unknown | 02 Jun 2014 | 02 Jun 2014 |
Aruba Networks, Inc. | Unknown | 02 Jun 2014 | 02 Jun 2014 |
Attachmate | Unknown | 02 Jun 2014 | 02 Jun 2014 |
AT&T | Unknown | 02 Jun 2014 | 02 Jun 2014 |
Avaya, Inc. | Unknown | 02 Jun 2014 | 02 Jun 2014 |
Barracuda Networks | Unknown | 02 Jun 2014 | 02 Jun 2014 |
Belkin, Inc. | Unknown | 02 Jun 2014 | 02 Jun 2014 |
Blue Coat Systems | Unknown | 02 Jun 2014 | 02 Jun 2014 |
Brocade | Unknown | 02 Jun 2014 | 02 Jun 2014 |
CVSS Metrics (Learn More)
Group | Score | Vector |
---|---|---|
Base | 6.4 | AV:A/AC:M/Au:N/C:C/I:P/A:N |
Temporal | 5.0 | E:POC/RL:OF/RC:C |
Environmental | 8.1 | CDP:H/TD:H/CR:H/IR:M/AR:L |
References
- https://www.openssl.org/news/secadv_20140605.txt
- http://ccsinjection.lepidum.co.jp/
- http://ccsinjection.lepidum.co.jp/blog/2014-06-05/CCS-Injection-en/index.html
- https://plus.google.com/app/basic/stream/z12xhp3hbzbhhjgfm22ncvtbeua1dpaa004
Credit
Thanks to KIKUCHI Masashi for reporting this vulnerability.
This document was written by Jared Allar.
Other Information
- CVE IDs: CVE-2014-0224
- Date Public: 05 6月 2014
- Date First Published: 05 6月 2014
- Date Last Updated: 05 6月 2014
- Document Revision: 17
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.