Vulnerability Name:

CVE-2014-8275

Assigned:2014-10-12
Published:2015-01-05
Updated:2017-11-14
Summary:OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k does not enforce certain constraints on certificate data, which allows remote attackers to defeat a fingerprint-based certificate-blacklist protection mechanism by including crafted data within a certificate's unsigned portion, related to crypto/asn1/a_verify.c, crypto/dsa/dsa_asn1.c, crypto/ecdsa/ecs_vrf.c, and crypto/x509/x_all.c.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
1.2 Low (CCN CVSS v2 Vector: AV:L/AC:H/Au:N/C:N/I:P/A:N)
0.9 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:H/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
4.3 Medium (REDHAT CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N)
3.2 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-310
References:Source: CONFIRM
Type: UNKNOWN
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10679

Source: APPLE
Type: UNKNOWN
APPLE-SA-2015-04-08-2

Source: FEDORA
Type: UNKNOWN
FEDORA-2015-0601

Source: SUSE
Type: UNKNOWN
openSUSE-SU-2015:0130

Source: SUSE
Type: UNKNOWN
SUSE-SU-2015:0578

Source: SUSE
Type: UNKNOWN
SUSE-SU-2015:0946

Source: SUSE
Type: UNKNOWN
openSUSE-SU-2015:1277

Source: SUSE
Type: UNKNOWN
openSUSE-SU-2016:0640

Source: HP
Type: UNKNOWN
HPSBUX03162

Source: HP
Type: UNKNOWN
SSRT101885

Source: HP
Type: UNKNOWN
SSRT101987

Source: HP
Type: UNKNOWN
HPSBHF03289

Source: HP
Type: UNKNOWN
HPSBOV03318

Source: HP
Type: UNKNOWN
HPSBMU03380

Source: HP
Type: UNKNOWN
HPSBMU03409

Source: HP
Type: UNKNOWN
HPSBMU03396

Source: HP
Type: UNKNOWN
HPSBMU03413

Source: HP
Type: UNKNOWN
HPSBMU03397

Source: REDHAT
Type: UNKNOWN
RHSA-2015:0066

Source: REDHAT
Type: UNKNOWN
RHSA-2015:0800

Source: CISCO
Type: UNKNOWN
20150310 Multiple Vulnerabilities in OpenSSL (January 2015) Affecting Cisco Products

Source: DEBIAN
Type: UNKNOWN
DSA-3125

Source: MANDRIVA
Type: UNKNOWN
MDVSA-2015:019

Source: MANDRIVA
Type: UNKNOWN
MDVSA-2015:062

Source: CONFIRM
Type: UNKNOWN
http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html

Source: CONFIRM
Type: UNKNOWN
http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html

Source: CONFIRM
Type: UNKNOWN
http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html

Source: CONFIRM
Type: UNKNOWN
http://www.oracle.com/technetwork/topics/security/cpuapr2015-2365600.html

Source: CONFIRM
Type: UNKNOWN
http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html

Source: CONFIRM
Type: UNKNOWN
http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html

Source: BID
Type: UNKNOWN
71935

Source: SECTRACK
Type: UNKNOWN
1033378

Source: CONFIRM
Type: UNKNOWN
https://bto.bluecoat.com/security-advisory/sa88

Source: XF
Type: UNKNOWN
openssl-cve20148275-sec-bypass(99709)

Source: CONFIRM
Type: UNKNOWN
https://github.com/openssl/openssl/commit/684400ce192dac51df3d3e92b61830a6ef90be3e

Source: CONFIRM
Type: UNKNOWN
https://github.com/openssl/openssl/commit/cb62ab4b17818fe66d2fed0a7fe71969131c811b

Source: CONFIRM
Type: UNKNOWN
https://kc.mcafee.com/corporate/index?page=content&id=SB10102

Source: CONFIRM
Type: UNKNOWN
https://kc.mcafee.com/corporate/index?page=content&id=SB10108

Source: CONFIRM
Type: UNKNOWN
https://support.apple.com/HT204659

Source: CONFIRM
Type: UNKNOWN
https://support.citrix.com/article/CTX216642

Source: CONFIRM
Type: VENDOR_ADVISORY
https://www.openssl.org/news/secadv_20150108.txt

Vulnerable Configuration:Configuration 1:
  • cpe:/a:openssl:openssl:0.9.8zc:*:*:*:*:*:*:*
  • OR cpe:/a:openssl:openssl:1.0.0a:*:*:*:*:*:*:*
  • OR cpe:/a:openssl:openssl:1.0.0b:*:*:*:*:*:*:*
  • OR cpe:/a:openssl:openssl:1.0.0c:*:*:*:*:*:*:*
  • OR cpe:/a:openssl:openssl:1.0.0d:*:*:*:*:*:*:*
  • OR cpe:/a:openssl:openssl:1.0.0e:*:*:*:*:*:*:*
  • OR cpe:/a:openssl:openssl:1.0.0f:*:*:*:*:*:*:*
  • OR cpe:/a:openssl:openssl:1.0.0g:*:*:*:*:*:*:*
  • OR cpe:/a:openssl:openssl:1.0.0h:*:*:*:*:*:*:*
  • OR cpe:/a:openssl:openssl:1.0.0i:*:*:*:*:*:*:*
  • OR cpe:/a:openssl:openssl:1.0.0j:*:*:*:*:*:*:*
  • OR cpe:/a:openssl:openssl:1.0.0k:*:*:*:*:*:*:*
  • OR cpe:/a:openssl:openssl:1.0.0l:*:*:*:*:*:*:*
  • OR cpe:/a:openssl:openssl:1.0.0m:*:*:*:*:*:*:*
  • OR cpe:/a:openssl:openssl:1.0.0n:*:*:*:*:*:*:*
  • OR cpe:/a:openssl:openssl:1.0.0o:*:*:*:*:*:*:*
  • OR cpe:/a:openssl:openssl:1.0.1a:*:*:*:*:*:*:*
  • OR cpe:/a:openssl:openssl:1.0.1b:*:*:*:*:*:*:*
  • OR cpe:/a:openssl:openssl:1.0.1c:*:*:*:*:*:*:*
  • OR cpe:/a:openssl:openssl:1.0.1d:*:*:*:*:*:*:*
  • OR cpe:/a:openssl:openssl:1.0.1e:*:*:*:*:*:*:*
  • OR cpe:/a:openssl:openssl:1.0.1f:*:*:*:*:*:*:*
  • OR cpe:/a:openssl:openssl:1.0.1g:*:*:*:*:*:*:*
  • OR cpe:/a:openssl:openssl:1.0.1h:*:*:*:*:*:*:*
  • OR cpe:/a:openssl:openssl:1.0.1i:*:*:*:*:*:*:*
  • OR cpe:/a:openssl:openssl:1.0.1j:*:*:*:*:*:*:*

  • Configuration RedHat 1:
  • cpe:/o:redhat:enterprise_linux:7:*:*:*:*:*:*:*

  • Configuration RedHat 2:
  • cpe:/o:redhat:enterprise_linux:6:*:*:*:*:*:*:*

  • Configuration RedHat 3:
  • cpe:/o:redhat:enterprise_linux:5:*:*:*:*:*:*:*

  • Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20148275
    V
    CVE-2014-8275
    2017-11-19
    oval:org.cisecurity:def:205
    P
    DSA-3125-1 -- openssl -- security update
    2016-02-08
    oval:org.mitre.oval:def:28514
    P
    RHSA-2015:0800 -- openssl security update (Moderate)
    2015-08-17
    oval:org.mitre.oval:def:28810
    V
    Potential security vulnerabilities have been identified with HP-UX running OpenSSL.These vulnerabilities could be exploited remotely to create a remote Denial of Service(DoS) and other vulnerabilites.
    2015-05-11
    oval:com.redhat.rhsa:def:20150800
    P
    RHSA-2015:0800: openssl security update (Moderate)
    2015-04-13
    oval:com.redhat.rhsa:def:20150066
    P
    RHSA-2015:0066: openssl security update (Moderate)
    2015-01-21
    oval:com.ubuntu.xenial:def:20148275000
    V
    CVE-2014-8275 on Ubuntu 16.04 LTS (xenial) - low.
    2015-01-08
    oval:com.ubuntu.precise:def:20148275000
    V
    CVE-2014-8275 on Ubuntu 12.04 LTS (precise) - low.
    2015-01-08
    oval:com.ubuntu.trusty:def:20148275000
    V
    CVE-2014-8275 on Ubuntu 14.04 LTS (trusty) - low.
    2015-01-08
    BACK
    openssl openssl 0.9.8zc
    openssl openssl 1.0.0a
    openssl openssl 1.0.0b
    openssl openssl 1.0.0c
    openssl openssl 1.0.0d
    openssl openssl 1.0.0e
    openssl openssl 1.0.0f
    openssl openssl 1.0.0g
    openssl openssl 1.0.0h
    openssl openssl 1.0.0i
    openssl openssl 1.0.0j
    openssl openssl 1.0.0k
    openssl openssl 1.0.0l
    openssl openssl 1.0.0m
    openssl openssl 1.0.0n
    openssl openssl 1.0.0o
    openssl openssl 1.0.1a
    openssl openssl 1.0.1b
    openssl openssl 1.0.1c
    openssl openssl 1.0.1d
    openssl openssl 1.0.1e
    openssl openssl 1.0.1f
    openssl openssl 1.0.1g
    openssl openssl 1.0.1h
    openssl openssl 1.0.1i
    openssl openssl 1.0.1j
    redhat enterprise_linux 7
    redhat enterprise_linux 6
    redhat enterprise_linux 5