CVE-2014-0160: OpenSSL Information Disclosure Vulnerability

High severity, CVSS 7.5. Actively exploited: in CISA KEV since 2022-05-04. EPSS: 100% chance of exploitation in the next 30 days.

The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.

Affected products

  • Broadcom Symantec Messaging Gateway: version 10.6.0 only; version 10.6.1 only
  • Canonical Ubuntu Linux: version 12.04 only; version 12.10 only; version 13.10 only
  • Debian Debian Linux: version 6.0 only; version 7.0 only; version 8.0 only
  • Fedoraproject Fedora: version 19 only; version 20 only
  • Filezilla-Project Filezilla Server: before 0.9.44 (fixed in 0.9.44)
  • Intellian v100 Firmware: version 1.20 only; version 1.21 only; version 1.24 only
  • Intellian v60 Firmware: version 1.15 only; version 1.25 only
  • Mitel MiCollab: version 6.0 only; version 7.0 only; version 7.1 only; version 7.2 only; version 7.3 only; version 7.3.0.104 only
  • Mitel MiVoice: version 1.1.2.5 only; version 1.1.3.3 only; version 1.2.0.11 only; version 1.3.2.2 only; version 1.4.0.102 only
  • OpenSSL OpenSSL: from 1.0.1, before 1.0.1g (fixed in 1.0.1g)
  • Opensuse Opensuse: version 12.3 only; version 13.1 only
  • Red Hat Enterprise Linux Desktop: version 6.0 only
  • Red Hat Enterprise Linux Server: version 6.0 only
  • Red Hat Enterprise Linux Server Aus: version 6.5 only
  • Red Hat Enterprise Linux Server Eus: version 6.5 only
  • Red Hat Enterprise Linux Server Tus: version 6.5 only
  • Red Hat Enterprise Linux Workstation: version 6.0 only
  • Red Hat Gluster Storage: version 2.1 only
  • Red Hat Storage: version 2.1 only
  • Red Hat Virtualization: version 6.0 only
  • Ricon s9922l Firmware: version 16.10.3(3794) only
  • Siemens Application Processing Engine Firmware: version 2.0 only
  • Siemens CP 1543-1 Firmware: version 1.1 only
  • Siemens Elan-8.2: before 8.3.3 (fixed in 8.3.3)
  • Siemens SIMATIC s7-1500 Firmware: version 1.5 only
  • and 3 more

Published 2014-04-07. Last modified 2026-06-17.