The ssl23_get_client_hello function in s23_srvr.c in OpenSSL 0.9.8zc, 1.0.0o, and 1.0.1j does not properly handle attempts to use unsupported protocols, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an unexpected handshake, as demonstrated by an SSLv3 handshake to a no-ssl3 application with certain error handling. NOTE: this issue became relevant after the CVE-2014-3568 fix.
CVSS Details
- CVSS 3.1 Base Score: 3.7
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade openssl | Aug 30, 2017 | Jan 8, 2015 |
| Apple Osx Adminframework | — | Upgrade macOS to the latest versionApply OS X security update 2015-004 | Aug 28, 2015 | Dec 24, 2014 |
| Apple Osx Openssl | — | Upgrade macOS to the latest versionApply OS X security update 2015-004 | Mar 29, 2016 | Dec 24, 2014 |
| Cisco Anyconnect | — | Upgrade to the latest version of Cisco Secure Client to resolve this vulnerability. | Dec 16, 2020 | Dec 24, 2014 |
| Cisco Apic | — | Upgrade to the latest version of Cisco APIC to resolve this vulnerability. | May 11, 2026 | Mar 10, 2015 |
| Cisco Asa | — | Upgrade to the latest version of Cisco ASA to resolve this vulnerability. | Oct 21, 2021 | Dec 24, 2014 |
| Cisco Ise | — | — | Oct 21, 2025 | Mar 10, 2015 |
| Cisco Xr Os | — | Upgrade to the latest version of Cisco IOS-XR to resolve this vulnerability. | May 19, 2021 | Mar 10, 2015 |
| Debian | — | Upgrade openssl | Jul 30, 2024 | Dec 24, 2014 |
| Freebsd | — | Upgrade FreeBSDUpgrade linux-c6-opensslUpgrade opensslUpgrade mingw32-openssl | Dec 10, 2025 | Jan 8, 2015 |
| Hpsim | — | Upgrade to the latest version of HP Systems Insight Manager | Oct 13, 2015 | Dec 24, 2014 |
| Hpsmh | — | Upgrade to the latest version of HP System Management Homepage | Oct 13, 2015 | Dec 24, 2014 |
| Hpux | — | Update openssl.OPENSSL-PVT to the latest versionUpdate openssl.OPENSSL-CONF to the latest versionUpdate openssl.OPENSSL-CER to the latest versionUpdate openssl.OPENSSL-RUN to the latest versionUpdate openssl.OPENSSL-PRNG to the latest versionUpdate openssl.OPENSSL-SRC to the latest versionUpdate openssl.OPENSSL-INC to the latest versionUpdate openssl.OPENSSL-LIB to the latest versionUpdate openssl.OPENSSL-MIS to the latest versionUpdate openssl.OPENSSL-DOC to the latest versionUpdate openssl.OPENSSL-MAN to the latest version | Aug 11, 2017 | Dec 24, 2014 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | Jan 9, 2015 | Dec 24, 2014 |
| Oracle Solaris | — | Upgrade database/mysql-55/client to version 5.5.56-0.175.3.21.0.4.0 on Solaris 11.3Upgrade database/mysql-56/client to version 5.6.36-0.175.3.21.0.4.0 on Solaris 11.3Upgrade database/mysql-55/tests to version 5.5.56-0.175.3.21.0.4.0 on Solaris 11.3Upgrade database/mysql-57/tests to version 5.7.17-0.175.3.19.0.2.0 on Solaris 11.3Upgrade database/mysql-56 to version 5.6.36-0.175.3.21.0.4.0 on Solaris 11.3Upgrade database/mysql-56/tests to version 5.6.36-0.175.3.21.0.4.0 on Solaris 11.3Upgrade database/mysql-55 to version 5.5.56-0.175.3.21.0.4.0 on Solaris 11.3Upgrade library/security/openssl/openssl-fips-140 to version 2.0.6-0.175.2.7.0.2.0 on Solaris 11.2Upgrade database/mysql-57/library to version 5.7.17-0.175.3.19.0.2.0 on Solaris 11.3Upgrade database/mysql-57 to version 5.7.17-0.175.3.19.0.2.0 on Solaris 11.3Upgrade database/mysql-55/library to version 5.5.56-0.175.3.21.0.4.0 on Solaris 11.3Upgrade database/mysql-57/embedded to version 5.7.17-0.175.3.19.0.2.0 on Solaris 11.3Upgrade runtime/perl-512 to version 5.12.5-0.175.3.19.0.2.0 on Solaris 11.3Upgrade runtime/perl-threaded-512 to version 5.12.5-0.175.3.19.0.2.0 on Solaris 11.3Upgrade library/security/openssl to version 1.0.1.11-0.175.2.7.0.2.0 on Solaris 11.2Upgrade database/mysql-57/client to version 5.7.17-0.175.3.19.0.2.0 on Solaris 11.3Upgrade compress/unzip to version 6.0-0.175.2.6.0.5.0 on Solaris 11.2Upgrade database/mysql-56/library to version 5.6.36-0.175.3.21.0.4.0 on Solaris 11.3 | May 29, 2017 | Dec 24, 2014 |
| Pulse Secure Pulse Connect Secure | — | Update Pulse Connect Secure to version 8.0R10Update Pulse Connect Secure to version 7.1R22Update Pulse Connect Secure to version 8.1R2.1 | Oct 28, 2020 | Dec 24, 2014 |
| Suse | — | Upgrade libopenssl1_1-hmacUpgrade libopenssl-1_0_0-develUpgrade libmysql55client18-x86Upgrade libopenssl10Upgrade libmysqlclient15-32bitUpgrade libmysql55client_r18Upgrade libopenssl1_1-32bitUpgrade libmysqlclient_r15Upgrade libopenssl1_0_0Upgrade libmysql55client_r18-32bitUpgrade openssl-1_1Upgrade libmysqlclient_r15-x86Upgrade mysqlUpgrade libopenssl-1_1-develUpgrade libmysqlclient_r15-32bitUpgrade libmysql55client18Upgrade libmysql55client18-32bitUpgrade libmysqlclient15Upgrade openssl-1_0_0Upgrade libopenssl-1_1-devel-32bitUpgrade opensslUpgrade libopenssl1_1-hmac-32bitUpgrade libmysqlclient15-x86Upgrade libopenssl1_1Upgrade libmysql55client_r18-x86Upgrade mysql-toolsUpgrade libopenssl-develUpgrade mysql-client | Dec 18, 2015 | Dec 24, 2014 |
| Ubuntu | — | Upgrade openssl | Nov 19, 2024 | Dec 24, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub