Vulnerability Database

296,172

Total vulnerabilities in the database

CVE-2014-5139

The ssl_set_client_disabled function in t1_lib.c in OpenSSL 1.0.1 before 1.0.1i allows remote SSL servers to cause a denial of service (NULL pointer dereference and client application crash) via a ServerHello message that includes an SRP ciphersuite without the required negotiation of that ciphersuite with the client.

  • Published: Aug 14, 2014
  • Updated: Apr 13, 2023
  • CVE: CVE-2014-5139
  • Severity: Low
  • Exploit:

CVSS v2:

  • Severity: Low
  • Score: 4.3
  • AV:N/AC:M/Au:N/C:N/I:N/A:P

No CWE or OWASP classifications available.

Software From Fixed in
openssl / openssl 1.0.1-beta2 1.0.1-beta2.x
openssl / openssl 1.0.1h 1.0.1h.x
openssl / openssl 1.0.1c 1.0.1c.x
openssl / openssl 1.0.1g 1.0.1g.x
openssl / openssl 1.0.1-beta3 1.0.1-beta3.x
openssl / openssl 1.0.1a 1.0.1a.x
openssl / openssl 1.0.1-beta1 1.0.1-beta1.x
openssl / openssl 1.0.1d 1.0.1d.x
openssl / openssl 1.0.1b 1.0.1b.x
openssl / openssl 1.0.1e 1.0.1e.x
openssl / openssl 1.0.1f 1.0.1f.x
openssl / openssl 1.0.1 1.0.1.x