CVE-2014-3470: Fedoraproject Fedora
Medium severity, CVSS 4.3. EPSS: 85.8% chance of exploitation in the next 30 days.
The ssl3_send_client_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h, when an anonymous ECDH cipher suite is used, allows remote attackers to cause a denial of service (NULL pointer dereference and client crash) by triggering a NULL certificate value.
Affected products
- Fedoraproject Fedora: any version; version 19 only; version 20 only
- MariaDB MariaDB: from 10.0.0, before 10.0.13 (fixed in 10.0.13)
- OpenSSL OpenSSL: before 0.9.8za (fixed in 0.9.8za); from 1.0.0, before 1.0.0m (fixed in 1.0.0m); from 1.0.1, before 1.0.1h (fixed in 1.0.1h)
- Opensuse Leap: version 42.1 only
- Opensuse Opensuse: version 13.2 only
- Red Hat Enterprise Linux: version 5 only; version 6.0 only
- Red Hat Storage: version 2.1 only
- Suse Linux Enterprise Desktop: version 12 only
- Suse Linux Enterprise Server: version 12 only
- Suse Linux Enterprise Software Development Kit: version 12 only
- Suse Linux Enterprise Workstation Extension: version 12 only
Published 2014-06-05. Last modified 2026-06-17.