CVE-2014-2901: High severity wolfSSL wolfssl vulnerability
Published Nov 19, 2014
·Updated
wolfssl before 3.2.0 does not properly issue certificates for a server's hostname.
Affected Software
2 affected componentsFixes available
wolfSSL wolfssl<3.2.0
debian/wolfssl
4.6.0+p1-0+deb11u25.5.4-2+deb12u25.7.2-0.1+deb13u15.8.4-1
Event History
Nov 19, 2014
Data Sourced
via Debian·10:21 PM
SeverityAffected Software
Nov 21, 2019
CVE Published
via MITRE·10:02 PM
Data Sourced
via MITRE·10:02 PM
Description
Feb 18, 2026
Data Sourced
via Debian·06:56 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID is CVE-2014-2901.
2
What is the severity level of CVE-2014-2901?
The severity level of CVE-2014-2901 is high.
3
What is the affected software for CVE-2014-2901?
The affected software for CVE-2014-2901 is Wolfssl before version 3.2.0.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2014-2901?
The CWE ID for CVE-2014-2901 is CWE-295.
5
How can I fix the vulnerability CVE-2014-2901?
To fix CVE-2014-2901, upgrade to Wolfssl version 3.2.0 or higher.