CVE-2014-3513: Input Validation
Published Oct 19, 2014
·Updated
Memory leak in d1srtp.c in the DTLS SRTP extension in OpenSSL 1.0.1 before 1.0.1j allows remote attackers to cause a denial of service (memory consumption) via a crafted handshake message.
Affected Software
13 affected components
OpenSSL OpenSSL=1.0.1
OpenSSL OpenSSL=1.0.1-beta1
OpenSSL OpenSSL=1.0.1-beta2
OpenSSL OpenSSL=1.0.1-beta3
OpenSSL OpenSSL=1.0.1a
OpenSSL OpenSSL=1.0.1b
OpenSSL OpenSSL=1.0.1c
OpenSSL OpenSSL=1.0.1d
OpenSSL OpenSSL=1.0.1e
OpenSSL OpenSSL=1.0.1f
OpenSSL OpenSSL=1.0.1g
OpenSSL OpenSSL=1.0.1h
OpenSSL OpenSSL=1.0.1i
Remediation
Patch Available
Patch Available
Event History
Oct 19, 2014
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-3513?
CVE-2014-3513 is classified as a moderate severity vulnerability due to its potential to cause denial of service.
2
How do I fix CVE-2014-3513?
The best way to fix CVE-2014-3513 is to upgrade OpenSSL to version 1.0.1j or later.
3
What types of software are affected by CVE-2014-3513?
CVE-2014-3513 affects various versions of OpenSSL 1.0.1, including beta releases and patch versions.
4
What does CVE-2014-3513 exploit?
CVE-2014-3513 exploits a memory leak in the DTLS SRTP extension during the handshake process.
5
What are the potential impacts of CVE-2014-3513?
The potential impacts of CVE-2014-3513 include denial of service through excessive memory consumption.