CVE-2014-0221: Fedoraproject Fedora
Medium severity, CVSS 4.3. EPSS: 87.9% chance of exploitation in the next 30 days.
The dtls1_get_message_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h allows remote attackers to cause a denial of service (recursion and client crash) via a DTLS hello message in an invalid DTLS handshake.
Affected products
- Fedoraproject Fedora: any version; version 19 only; version 20 only
- MariaDB MariaDB: from 10.0.0, before 10.0.13 (fixed in 10.0.13)
- OpenSSL OpenSSL: from 0.9.8, before 0.9.8za (fixed in 0.9.8za); from 1.0.0, before 1.0.0m (fixed in 1.0.0m); from 1.0.1, before 1.0.1h (fixed in 1.0.1h)
- Opensuse Leap: version 42.1 only
- Opensuse Opensuse: version 13.2 only
- Red Hat Enterprise Linux: version 5 only; version 6.0 only
- Red Hat Storage: version 2.1 only
- Suse Linux Enterprise Desktop: version 12 only
- Suse Linux Enterprise Server: version 12 only
- Suse Linux Enterprise Software Development Kit: version 12 only
- Suse Linux Enterprise Workstation Extension: version 12 only
Published 2014-06-05. Last modified 2026-06-17.