CVE-2014-0195: Fedoraproject Fedora
Medium severity, CVSS 6.8. EPSS: 100% chance of exploitation in the next 30 days.
The dtls1_reassemble_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly validate fragment lengths in DTLS ClientHello messages, which allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via a long non-initial fragment.
Affected products
- Fedoraproject Fedora: version 19 only; version 20 only
- MariaDB MariaDB: from 10.0.0, before 10.0.13 (fixed in 10.0.13)
- OpenSSL OpenSSL: from 0.9.8, before 0.9.8za (fixed in 0.9.8za); from 1.0.0, before 1.0.0m (fixed in 1.0.0m); from 1.0.1, before 1.0.1h (fixed in 1.0.1h)
- Opensuse Leap: version 42.1 only
- Opensuse Opensuse: version 13.2 only
Published 2014-06-05. Last modified 2026-06-17.