CVE-2014-3513

Memory leak in d1_srtp.c in the DTLS SRTP extension in OpenSSL 1.0.1 before 1.0.1j allows remote attackers to cause a denial of service (memory consumption) via a crafted handshake message.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.1 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 97%
Affected Products (NVD)
VendorProductVersion
opensslopenssl
1.0.1
opensslopenssl
1.0.1:beta1
opensslopenssl
1.0.1:beta2
opensslopenssl
1.0.1:beta3
opensslopenssl
1.0.1a:a
opensslopenssl
1.0.1b:b
opensslopenssl
1.0.1c:c
opensslopenssl
1.0.1d:d
opensslopenssl
1.0.1e:e
opensslopenssl
1.0.1f:f
opensslopenssl
1.0.1g:g
opensslopenssl
1.0.1h:h
opensslopenssl
1.0.1i:i
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
openssl
bookworm
3.0.14-1~deb12u1
fixed
bookworm (security)
3.0.14-1~deb12u2
fixed
bullseye
1.1.1w-0+deb11u1
fixed
bullseye (security)
1.1.1w-0+deb11u2
fixed
sid
3.3.2-2
fixed
squeeze
not-affected
trixie
3.3.2-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
openssl
lucid
not-affected
precise
Fixed 1.0.1-4ubuntu5.20
released
trusty
Fixed 1.0.1f-1ubuntu2.7
released
openssl098
lucid
dne
precise
not-affected
trusty
dne
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libopenssl-devel
suse enterprise desktop 15 SP6
3.1.4-150600.2.1
fixed
suse enterprise desktop 15 SP7
3.2.3-150700.1.1
fixed
suse enterprise sap 15 SP6
3.1.4-150600.2.1
fixed
suse enterprise sap 15 SP7
3.2.3-150700.1.1
fixed
suse enterprise server 15 SP6
3.1.4-150600.2.1
fixed
suse enterprise server 15 SP7
3.2.3-150700.1.1
fixed
libopenssl-fips-provider
suse enterprise desktop 15 SP6
3.1.4-150600.2.1
fixed
suse enterprise desktop 15 SP7
3.2.3-150700.1.1
fixed
suse enterprise sap 15 SP6
3.1.4-150600.2.1
fixed
suse enterprise sap 15 SP7
3.2.3-150700.1.1
fixed
suse enterprise server 15 SP6
3.1.4-150600.2.1
fixed
suse enterprise server 15 SP7
3.2.3-150700.1.1
fixed
openssl
suse enterprise desktop 15 SP6
3.1.4-150600.2.1
fixed
suse enterprise desktop 15 SP7
3.2.3-150700.1.1
fixed
suse enterprise sap 15 SP6
3.1.4-150600.2.1
fixed
suse enterprise sap 15 SP7
3.2.3-150700.1.1
fixed
suse enterprise server 15 SP6
3.1.4-150600.2.1
fixed
suse enterprise server 15 SP7
3.2.3-150700.1.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
openssl
RHEL 6
0:1.0.1e-30.el6_6.2
fixed
RHEL 7
1:1.0.1e-34.el7_0.6
fixed
openssl-devel
RHEL 6
0:1.0.1e-30.el6_6.2
fixed
RHEL 7
1:1.0.1e-34.el7_0.6
fixed
openssl-libs
RHEL 7
1:1.0.1e-34.el7_0.6
fixed
openssl-perl
RHEL 6
0:1.0.1e-30.el6_6.2
fixed
RHEL 7
1:1.0.1e-34.el7_0.6
fixed
openssl-static
RHEL 6
0:1.0.1e-30.el6_6.2
fixed
RHEL 7
1:1.0.1e-34.el7_0.6
fixed
References