CVE-2014-0224: Fedoraproject Fedora
High severity, CVSS 7.4. EPSS: 95.3% chance of exploitation in the next 30 days.
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive information, via a crafted TLS handshake, aka the "CCS Injection" vulnerability.
Affected products
- Fedoraproject Fedora: version 19 only; version 20 only
- Filezilla-Project Filezilla Server: before 0.9.45 (fixed in 0.9.45)
- MariaDB MariaDB: from 10.0.0, before 10.0.13 (fixed in 10.0.13)
- Node.js Node.js: before 0.10.29 (fixed in 0.10.29)
- OpenSSL OpenSSL: before 0.9.8za (fixed in 0.9.8za); from 1.0.0, before 1.0.0m (fixed in 1.0.0m); from 1.0.1, before 1.0.1h (fixed in 1.0.1h)
- Opensuse Opensuse: version 13.1 only; version 13.2 only
- Python Python: from 2.7.0, before 2.7.8 (fixed in 2.7.8); from 3.4.0, before 3.4.2 (fixed in 3.4.2)
- Red Hat Enterprise Linux: version 4 only; version 5 only; version 6.0 only
- Red Hat JBoss Enterprise Application Platform: version 5.2.0 only; version 6.2.3 only
- Red Hat JBoss Enterprise Web Platform: version 5.2.0 only
- Red Hat JBoss Enterprise Web Server: version 2.0.1 only
- Red Hat Storage: version 2.1 only
- Siemens Application Processing Engine Firmware: before 2.0.2 (fixed in 2.0.2)
- Siemens CP1543-1 Firmware: before 1.1.25 (fixed in 1.1.25)
- Siemens Rox Firmware: before 1.16.1 (fixed in 1.16.1)
- Siemens s7-1500 Firmware: before 1.6 (fixed in 1.6)
Published 2014-06-05. Last modified 2026-06-17.