Oval Definition:oval:org.mitre.oval:def:24241
Revision Date:2014-07-14Version:50
Title:The TLS and DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read
Description:The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2014-0160
Platform(s):Microsoft Windows 7
Microsoft Windows 8
Microsoft Windows 8.1
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Server 2012
Microsoft Windows Server 2012 R2
Microsoft Windows Vista
Microsoft Windows XP
Product(s):OpenSSL
Definition Synopsis
  • Check vulnerable OpenSSL
  • Check if the version of OpenSSL 1.0.1 before 1.0.1g
  • AND OpenSSL is installed
  • OR Check vulnerable OpenSSL (32_bit)
  • Check if the version of OpenSSL 1.0.1 before 1.0.1g (32_bit)
  • AND OpenSSL (32_bit) is installed
  • OR Check if the version of ssleay32.dll 1.0.1 before 1.0.1g ProgramFilesDir
  • OR Check if the version of ssleay32.dll 1.0.1 before 1.0.1g ProgramFilesDir x86
  • OR Check if the version of ssleay32.dll 1.0.1 before 1.0.1g under Sytem32 and SysWOW64
  • BACK