Kaspersky ID:
KLA10460
Дата обнаружения:
08/01/2015
Обновлено:
12/04/2024

Описание

Multiple serious vulnerabilities have been found in OpenSSL. Malicious users can exploit these vulnerabilities to cause denial of service or bypass security restrictions.

Below is a complete list of vulnerabilities pppeep

  1. An unknown vulnerability can be exploited remotely via specially designed DTLS message;
  2. Improper calculations can be exploited remotely via unspecified vectors;
  3. An unknown vulnerability can be exploited remotely via unspecified vectors related to ServerKeyExchange, fingerprint-based certificate-blacklist, Diffie-Hellman certificate;
  4. Lack of protocol checking can be exploited remotely via unexpected handshake;
  5. An unknown vulnerability can be exploited remotely via RSA-to-EXPORT_RSA downgrade attacks;
  6. Memory leak can be exploited remotely via specially designed records.

Первичный источник обнаружения

Эксплуатация

Public exploits exist for this vulnerability.

Связанные продукты

Список CVE

  • CVE-2014-3571
    warning
  • CVE-2014-8275
    warning
  • CVE-2014-3569
    warning
  • CVE-2014-3572
    warning
  • CVE-2014-3570
    warning
  • CVE-2015-0206
    warning
  • CVE-2015-0204
    warning
  • CVE-2015-0205
    warning

Смотрите также

Узнай статистику распространения уязвимостей в своем регионе statistics.securelist.com

Нашли неточность в описании этой уязвимости? Дайте нам знать!
Встречай новый Kaspersky!
Каждая минута твоей онлайн-жизни заслуживает топовой защиты.
Узнать больше
Kaspersky IT Security Calculator:
Оцените ваш профиль кибербезопасности
Узнать больше
Confirm changes?
Your message has been sent successfully.