Vulnerability Database

289,689

Total vulnerabilities in the database

CVE-2014-0195

The dtls1_reassemble_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly validate fragment lengths in DTLS ClientHello messages, which allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via a long non-initial fragment.

  • Published: Jun 5, 2014
  • Updated: Apr 13, 2023
  • CVE: CVE-2014-0195
  • Severity: Medium
  • Exploit:

CVSS v2:

  • Severity: Medium
  • Score: 6.8
  • AV:N/AC:M/Au:N/C:P/I:P/A:P

CWEs:

Software From Fixed in
openssl / openssl 1.0.0 1.0.0m
openssl / openssl 1.0.1 1.0.1h
openssl / openssl 0.9.8 0.9.8za
mariadb / mariadb 10.0.0 10.0.13
opensuse / leap 42.1 42.1.x
opensuse / opensuse 13.2 13.2.x
fedoraproject / fedora 20 20.x
fedoraproject / fedora 19 19.x