Vulnerability Database

296,172

Total vulnerabilities in the database

CVE-2013-6450

The DTLS retransmission implementation in OpenSSL 1.0.0 before 1.0.0l and 1.0.1 before 1.0.1f does not properly maintain data structures for digest and encryption contexts, which might allow man-in-the-middle attackers to trigger the use of a different context and cause a denial of service (application crash) by interfering with packet delivery, related to ssl/d1_both.c and ssl/t1_enc.c.

  • Published: Jan 1, 2014
  • Updated: Apr 13, 2023
  • CVE: CVE-2013-6450
  • Severity: Medium
  • Exploit:

CVSS v2:

  • Severity: Medium
  • Score: 5.8
  • AV:N/AC:M/Au:N/C:N/I:P/A:P

CWEs:

Software From Fixed in
openssl / openssl 1.0.1-beta2 1.0.1-beta2.x
openssl / openssl 1.0.0c 1.0.0c.x
openssl / openssl 1.0.0i 1.0.0i.x
openssl / openssl 1.0.0-beta1 1.0.0-beta1.x
openssl / openssl 1.0.0-beta2 1.0.0-beta2.x
openssl / openssl 1.0.1c 1.0.1c.x
openssl / openssl 1.0.0h 1.0.0h.x
openssl / openssl 1.0.0-beta3 1.0.0-beta3.x
openssl / openssl 1.0.0e 1.0.0e.x
openssl / openssl 1.0.1-beta3 1.0.1-beta3.x
openssl / openssl 1.0.0f 1.0.0f.x
openssl / openssl 1.0.0d 1.0.0d.x
openssl / openssl 1.0.0j 1.0.0j.x
openssl / openssl 1.0.1a 1.0.1a.x
openssl / openssl 1.0.1-beta1 1.0.1-beta1.x
openssl / openssl 1.0.1d 1.0.1d.x
openssl / openssl 1.0.0-beta4 1.0.0-beta4.x
openssl / openssl 1.0.0 1.0.0.x
openssl / openssl 1.0.1b 1.0.1b.x
openssl / openssl 1.0.1e 1.0.1e.x
openssl / openssl 1.0.0-beta5 1.0.0-beta5.x
openssl / openssl 1.0.0a 1.0.0a.x
openssl / openssl 1.0.0b 1.0.0b.x
openssl / openssl 1.0.1 1.0.1.x
openssl / openssl 1.0.0g 1.0.0g.x