CVE-2014-0224: Fedoraproject Fedora

High severity, CVSS 7.4. EPSS: 95.3% chance of exploitation in the next 30 days.

OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive information, via a crafted TLS handshake, aka the "CCS Injection" vulnerability.

Affected products

  • Fedoraproject Fedora: version 19 only; version 20 only
  • Filezilla-Project Filezilla Server: before 0.9.45 (fixed in 0.9.45)
  • MariaDB MariaDB: from 10.0.0, before 10.0.13 (fixed in 10.0.13)
  • Node.js Node.js: before 0.10.29 (fixed in 0.10.29)
  • OpenSSL OpenSSL: before 0.9.8za (fixed in 0.9.8za); from 1.0.0, before 1.0.0m (fixed in 1.0.0m); from 1.0.1, before 1.0.1h (fixed in 1.0.1h)
  • Opensuse Opensuse: version 13.1 only; version 13.2 only
  • Python Python: from 2.7.0, before 2.7.8 (fixed in 2.7.8); from 3.4.0, before 3.4.2 (fixed in 3.4.2)
  • Red Hat Enterprise Linux: version 4 only; version 5 only; version 6.0 only
  • Red Hat JBoss Enterprise Application Platform: version 5.2.0 only; version 6.2.3 only
  • Red Hat JBoss Enterprise Web Platform: version 5.2.0 only
  • Red Hat JBoss Enterprise Web Server: version 2.0.1 only
  • Red Hat Storage: version 2.1 only
  • Siemens Application Processing Engine Firmware: before 2.0.2 (fixed in 2.0.2)
  • Siemens CP1543-1 Firmware: before 1.1.25 (fixed in 1.1.25)
  • Siemens Rox Firmware: before 1.16.1 (fixed in 1.16.1)
  • Siemens s7-1500 Firmware: before 1.6 (fixed in 1.6)

Published 2014-06-05. Last modified 2026-06-17.