CVE-2014-0160
OpenSSL Information Disclosure Vulnerability is confirmed as actively exploited and is listed in the CISA KEV catalog.
Required action
Apply updates per vendor instructions.
CISA notes
https://nvd.nist.gov/vuln/detail/CVE-2014-0160
Description
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NAffected Products
| Vendor | Product | Affected versions |
|---|---|---|
| - | - | n/a |
References
128 Links- DSA-2896
- HPSBGN03008
- HPSBMU03024
- RHSA-2014:0396
- HPSBHF03021
- HPSBHF03136
- HPSBMU03033
- HPSBGN03011
- openSUSE-SU-2014:0492
- SSRT101846
- HPSBMU03037
- HPSBMU03012
- HPSBST03001
- HPSBMU03023
- 20140409 OpenSSL Heartbeat Extension Vulnerability in Multiple Cisco Products
- HPSBMU03044
- HPSBMU03030
- FEDORA-2014-4879
- FEDORA-2014-4910
- FEDORA-2014-9308
- HPSBMU03013
- RHSA-2014:0377
- HPSBMU02995
- HPSBPI03031
- HPSBMU02999
- HPSBGN03010
- HPSBMU03029
- HPSBMU03018
- HPSBMU03040
- HPSBMU03025
- HPSBST03016
- HPSBMU03028
- HPSBMU03009
- HPSBST03000
- HPSBST03004
- USN-2165-1
- RHSA-2014:0378
- HPSBMU02997
- SUSE-SA:2014:002
- HPSBMU02994
- HPSBMU03022
- HPSBST03027
- HPSBMU03019
- HPSBMU03062
- HPSBMU03020
- HPSBST03015
- RHSA-2014:0376
- HPSBPI03014
- MDVSA-2015:062
- openSUSE-SU-2014:0560
- HPSBMU03032
- HPSBMU02998
- HPSBMU03017
- 20140408 heartbleed OpenSSL bug CVE-2014-0160
- 20140409 Re: heartbleed OpenSSL bug CVE-2014-0160
- 20141205 NEW: VMSA-2014-0012 - VMware vSphere product updates address security vulnerabilities
- [syslog-ng-announce] 20140411 syslog-ng Premium Edition 5 LTS (5.0.4a) has been released
- 20140411 MRI Rubies may contain statically linked, vulnerable OpenSSL
- 20141205 NEW: VMSA-2014-0012 - VMware vSphere product updates address security vulnerabilities
- 20140408 Re: heartbleed OpenSSL bug CVE-2014-0160
- 20140412 Re: heartbleed OpenSSL bug CVE-2014-0160
- [tomcat-dev] 20190319 svn commit: r1855831 [26/30] - in /tomcat/site/trunk: ./ docs/ xdocs/
- [tomcat-dev] 20190325 svn commit: r1856174 [26/29] - in /tomcat/site/trunk: docs/ xdocs/ xdocs/stylesheets/
- [tomcat-dev] 20200203 svn commit: r1873527 [26/30] - /tomcat/site/trunk/docs/
- [tomcat-dev] 20200213 svn commit: r1873980 [31/34] - /tomcat/site/trunk/docs/
- https://support.f5.com/kb/en-us/solutions/public/15000/100/sol15159.html?sr=36517217
- http://www.getchef.com/blog/2014/04/09/chef-server-heartbleed-cve-2014-0160-releases/
- http://www.splunk.com/view/SP-CAAAMB3
- http://www.websense.com/support/article/kbarticle/Vulnerabilities-resolved-in-TRITON-APX-Version-8-0
- http://www.apcmedia.com/salestools/SJHN-7RKGNM/SJHN-7RKGNM_R4_EN.pdf
- http://www-01.ibm.com/support/docview.wss?uid=swg21670161
- http://www.vmware.com/security/advisories/VMSA-2014-0012.html
- http://www-01.ibm.com/support/docview.wss?uid=isg400001843
- http://www.innominate.com/data/downloads/manuals/mdm_1.5.2.1_Release_Notes.pdf
- https://filezilla-project.org/versions.php?type=server
- http://www.kerio.com/support/kerio-control/release-history
- http://advisories.mageia.org/MGASA-2014-0165.html
- http://www.blackberry.com/btsc/KB35882
- https://bugzilla.redhat.com/show_bug.cgi?id=1084875
- http://www-01.ibm.com/support/docview.wss?uid=isg400001841
- https://code.google.com/p/mod-spdy/issues/detail?id=85
- http://www.getchef.com/blog/2014/04/09/chef-server-11-0-12-release/
- http://heartbleed.com/
- http://download.schneider-electric.com/files?p_Doc_Ref=SEVD%202014-119-01
- http://cogentdatahub.com/ReleaseNotes.html
- http://www.f-secure.com/en/web/labs_global/fsc-2014-1
- https://blog.torproject.org/blog/openssl-bug-cve-2014-0160
- http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html
- http://www.oracle.com/technetwork/topics/security/opensslheartbleedcve-2014-0160-2188454.html
- https://support.f5.com/kb/en-us/solutions/public/15000/100/sol15159.html
- http://git.openssl.org/gitweb/?p=openssl.git%3Ba=commit%3Bh=96db9023b881d7cd9f379b0c154650d6c108e9a3
- http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20160512_00
- http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004661
- https://www.cert.fi/en/reports/2014/vulnerability788210.html
- http://blog.fox-it.com/2014/04/08/openssl-heartbleed-bug-live-blog/
- http://public.support.unisys.com/common/public/vulnerability/NVD_Detail_Rpt.aspx?ID=3
- http://www.getchef.com/blog/2014/04/09/enterprise-chef-11-1-3-release/
- https://www.mitel.com/en-ca/support/security-advisories/mitel-product-security-advisory-17-0008
- http://www.openssl.org/news/secadv_20140407.txt
- https://gist.github.com/chapmajs/10473815
- http://public.support.unisys.com/common/public/vulnerability/NVD_Detail_Rpt.aspx?ID=1
- http://support.citrix.com/article/CTX140605
- http://www.getchef.com/blog/2014/04/09/enterprise-chef-1-4-9-release/
- https://sku11army.blogspot.com/2020/01/heartbleed-hearts-continue-to-bleed.html
- https://cert-portal.siemens.com/productcert/pdf/ssa-635659.pdf
- https://yunus-shn.medium.com/ricon-industrial-cellular-router-heartbleed-attack-2634221c02bd
Record Details
CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Exploited-in-the-wild data from the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not endorsed or certified by MITRE, NVD, CISA, or FIRST.