CVE-2014-0198: Debian Linux

Medium severity, CVSS 4.3. EPSS: 43.8% chance of exploitation in the next 30 days.

The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, does not properly manage a buffer pointer during certain recursive calls, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors that trigger an alert condition.

Affected products

  • Debian Debian Linux: version 6.0 only; version 7.0 only; version 8.0 only
  • Fedoraproject Fedora: version 19 only; version 20 only
  • MariaDB MariaDB: from 10.0.0, before 10.0.13 (fixed in 10.0.13)
  • OpenSSL OpenSSL: from 1.0.0, up to and including 1.0.1g
  • Opensuse Opensuse: version 12.3 only; version 13.1 only
  • Suse Linux Enterprise Desktop: version 12 only
  • Suse Linux Enterprise Server: version 12 only
  • Suse Linux Enterprise Software Development Kit: version 12 only
  • Suse Linux Enterprise Workstation Extension: version 12 only

Published 2014-05-06. Last modified 2026-06-17.