CVE-2014-0221: Fedoraproject Fedora

Medium severity, CVSS 4.3. EPSS: 87.9% chance of exploitation in the next 30 days.

The dtls1_get_message_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h allows remote attackers to cause a denial of service (recursion and client crash) via a DTLS hello message in an invalid DTLS handshake.

Affected products

  • Fedoraproject Fedora: any version; version 19 only; version 20 only
  • MariaDB MariaDB: from 10.0.0, before 10.0.13 (fixed in 10.0.13)
  • OpenSSL OpenSSL: from 0.9.8, before 0.9.8za (fixed in 0.9.8za); from 1.0.0, before 1.0.0m (fixed in 1.0.0m); from 1.0.1, before 1.0.1h (fixed in 1.0.1h)
  • Opensuse Leap: version 42.1 only
  • Opensuse Opensuse: version 13.2 only
  • Red Hat Enterprise Linux: version 5 only; version 6.0 only
  • Red Hat Storage: version 2.1 only
  • Suse Linux Enterprise Desktop: version 12 only
  • Suse Linux Enterprise Server: version 12 only
  • Suse Linux Enterprise Software Development Kit: version 12 only
  • Suse Linux Enterprise Workstation Extension: version 12 only

Published 2014-06-05. Last modified 2026-06-17.