OpenSSL CVE-2014-3566 Man In The Middle Information Disclosure Vulnerability

BID:70574

Info

OpenSSL CVE-2014-3566 Man In The Middle Information Disclosure Vulnerability

Bugtraq ID: 70574
Class: Design Error
CVE: CVE-2014-3566
Remote: Yes
Local: No
Published: Oct 14 2014 12:00AM
Updated: Nov 03 2015 06:53PM
Credit: Bodo Moeller, Thai Duong, and Krzysztof Kotowicz of Google Security Team
Vulnerable: Xerox Phaser 7800 0
Xerox Phaser 6700 0
VMWare ESXi 5.0
Slackware Slackware Linux 13.37
Slackware Slackware Linux 13.0
RedHat Enterprise Linux Desktop Workstation 5 client
Red Hat Enterprise Linux Workstation Supplementary 6
Red Hat Enterprise Linux Workstation Optional 6
Red Hat Enterprise Linux Workstation 6
Red Hat Enterprise Linux Supplementary 5 server
Red Hat Enterprise Linux Server Supplementary 6
Red Hat Enterprise Linux Server Optional 6
Red Hat Enterprise Linux Server 6
Red Hat Enterprise Linux HPC Node Supplementary 6
Red Hat Enterprise Linux HPC Node Optional 6
Red Hat Enterprise Linux HPC Node 6
Red Hat Enterprise Linux Desktop Supplementary 6
Red Hat Enterprise Linux Desktop Supplementary 5 client
Red Hat Enterprise Linux Desktop Optional 6
Red Hat Enterprise Linux Desktop 6
Red Hat Enterprise Linux Desktop 5 client
Red Hat Enterprise Linux 5 Server
Oracle Enterprise Linux 6.2
Oracle Enterprise Linux 6
Oracle Enterprise Linux 5
OpenSSL Project OpenSSL 1.0 beta3
OpenSSL Project OpenSSL 1.0 Beta2
OpenSSL Project OpenSSL 1.0 beta1
OpenSSL Project OpenSSL 1.0
OpenSSL Project OpenSSL 0.9.8 k
OpenSSL Project OpenSSL 0.9.8 j
OpenSSL Project OpenSSL 0.9.8 i
OpenSSL Project OpenSSL 0.9.8 h
OpenSSL Project OpenSSL 0.9.8 e
OpenSSL Project OpenSSL 0.9.8 d
OpenSSL Project OpenSSL 0.9.8 c
OpenSSL Project OpenSSL 0.9.8 b
OpenSSL Project OpenSSL 0.9.8 a
OpenSSL Project OpenSSL 0.9.8
+ Gentoo Linux
OpenSSL Project OpenSSL 1.0.1c
OpenSSL Project OpenSSL 1.0.1a
OpenSSL Project OpenSSL 1.0.1
OpenSSL Project OpenSSL 1.0.0j
OpenSSL Project OpenSSL 1.0.0i
OpenSSL Project OpenSSL 1.0.0g
OpenSSL Project OpenSSL 1.0.0f
OpenSSL Project OpenSSL 1.0.0e
OpenSSL Project OpenSSL 1.0.0d
OpenSSL Project OpenSSL 1.0.0c
OpenSSL Project OpenSSL 1.0.0b
OpenSSL Project OpenSSL 1.0.0a
OpenSSL Project OpenSSL 1.0.0 Beta5
OpenSSL Project OpenSSL 1.0.0 Beta4
OpenSSL Project OpenSSL 0.9.8X
OpenSSL Project OpenSSL 0.9.8w
OpenSSL Project OpenSSL 0.9.8t
OpenSSL Project OpenSSL 0.9.8s
OpenSSL Project OpenSSL 0.9.8R
OpenSSL Project OpenSSL 0.9.8Q
OpenSSL Project OpenSSL 0.9.8p
OpenSSL Project OpenSSL 0.9.8o
OpenSSL Project OpenSSL 0.9.8n
OpenSSL Project OpenSSL 0.9.8m
OpenSSL Project OpenSSL 0.9.8l
OpenSSL Project OpenSSL 0.9.8g
OpenSSL Project OpenSSL 0.9.8f
OpenSSL Project OpenSSL 0.9.8v
Microsoft Windows Vista Service Pack 2 0
Microsoft Windows Server 2008 R2 for x64-based Systems SP1
Microsoft Windows Server 2008 for x64-based Systems SP2
Microsoft Windows Server 2008 for Itanium-based Systems SP2
Microsoft Windows Server 2008 for 32-bit Systems SP2
Microsoft Windows Server 2003 x64 SP2
Microsoft Windows Server 2003 Itanium SP2
Microsoft Windows Server 2003 SP2
Microsoft Windows 7 for x64-based Systems SP1
Microsoft Windows 7 for 32-bit Systems SP1
Juniper Networks SA6500 FIPS 0
Juniper Networks SA6000 FIPS 0
Juniper Networks SA2000 0
IBM WebSphere Process Server 7.0.4
IBM WebSphere MQ 7.0.1 .2
IBM WebSphere MQ 7.0.1 .1
IBM WebSphere MQ 7.0.1.5
IBM WebSphere MQ 7.0.1.4
IBM WebSphere MQ 7.0.1.3
IBM WebSphere MQ 7.0.1.0
IBM WebSphere MQ 7.0
IBM WebSphere Lombardi Edition 7.2.0
IBM WebSphere Lombardi Edition 7.2
IBM Websphere Application Server 7.0 3
IBM Websphere Application Server 7.0 21
IBM Websphere Application Server 7.0 .9
IBM Websphere Application Server 7.0 .8
IBM Websphere Application Server 7.0 .2
IBM Websphere Application Server 7.0 .13
IBM Websphere Application Server 7.0 .12
IBM Websphere Application Server 7.0 .11
IBM Websphere Application Server 8.0.0.4
IBM Websphere Application Server 8.0.0.1
IBM Websphere Application Server 8.0.0.0
IBM Websphere Application Server 8.0
IBM Websphere Application Server 7.0.0.7
IBM Websphere Application Server 7.0.0.6
IBM Websphere Application Server 7.0.0.5
IBM Websphere Application Server 7.0.0.4
IBM Websphere Application Server 7.0.0.23
IBM Websphere Application Server 7.0.0.19
IBM Websphere Application Server 7.0.0.17
IBM Websphere Application Server 7.0.0.15
IBM Websphere Application Server 7.0.0.14
IBM Websphere Application Server 7.0.0.1
IBM Websphere Application Server 7.0.0.0
IBM Websphere Application Server 7.0
IBM Websphere Application Server 6.1
IBM Web Experience Factory 7.0.1
IBM Web Experience Factory 7.0
IBM Tivoli Storage Productivity Center 4.2.1.185
IBM Tivoli Storage Productivity Center 4.2.1
IBM Tivoli Provisioning Manager for OS Deployment 5.1 3 Intirim Fix 3
IBM Tivoli Provisioning Manager for OS Deployment 5.1 .3
IBM Tivoli Provisioning Manager for OS Deployment 5.1 .116
IBM Tivoli Provisioning Manager for OS Deployment 5.1.Fix Pack 3
IBM Tivoli Provisioning Manager for OS Deployment 5.1.0.2
IBM Tivoli Provisioning Manager 5.1.1
IBM Tivoli Provisioning Manager 2.1
IBM Tivoli Provisioning Manager 5.1.1.1
IBM Tivoli Provisioning Manager 5.1.0.2
IBM Tivoli Netcool/OMNIbus 7.3
IBM Tivoli Netcool Performance Manager (TNPM Wireless) 1.3.1
IBM Tivoli Management Framework 4.1.1
IBM Tivoli Directory Server 6.3
IBM Tivoli Directory Server 6.2
IBM Tivoli Directory Server 6.1
IBM Tivoli Directory Server 6.0
IBM Tivoli Common Reporting 2.1
IBM Tivoli Business Service Manager 4.2.1
IBM Runtimes for Java Technology 6.0
IBM Runtimes for Java Technology 5.0
IBM Rational Team Concert 3.0
IBM Rational Team Concert 2.0
IBM Rational Software Architect 8
IBM Rational Software Architect 7.5.5.2
IBM Rational Software Architect 7.5
IBM Rational Software Architect 7.0
IBM Rational Policy Tester 8.5
IBM Rational Method Composer 7.2
IBM Rational ClearQuest 8.0.0.2
IBM Rational ClearQuest 8.0.0.1
IBM Rational ClearQuest 7.1.2.6
IBM Rational ClearQuest 7.1.2.2
IBM Rational ClearQuest 7.1.2.1
IBM Rational ClearQuest 7.1.2
IBM Rational ClearCase 7.1.2.2
IBM Rational ClearCase 7.1.1.5
IBM Rational ClearCase 7.1.1.4
IBM Rational ClearCase 7.1.0.1
IBM Lotus Domino 8.0.2
IBM Lotus Domino 8.0.1
IBM Lotus Domino 8.5
IBM Lotus Domino 8.0
IBM IBM Rational ClearQuest 8.0
IBM IBM Rational ClearQuest 7.1.2.5
IBM HTTP Server 7.0 .11
IBM HTTP Server 6.1 .31
IBM HTTP Server 6.1 .27
IBM HTTP Server 6.1 .25
IBM HTTP Server 6.1 .19
IBM HTTP Server 6.1 .17
IBM HTTP Server 6.1 .15
IBM HTTP Server 8.0.0.1
IBM HTTP Server 8.0
IBM HTTP Server 7.0.4.27
IBM HTTP Server 7.0.0.5
IBM HTTP Server 7.0.0.21
IBM HTTP Server 7.0.0.19
IBM HTTP Server 7.0.0.17
IBM HTTP Server 7.0.0.15
IBM HTTP Server 7.0.0.13
IBM HTTP Server 7.0
IBM HTTP Server 6.2
IBM HTTP Server 6.1.0.39
IBM HTTP Server 6.1.0.37
IBM HTTP Server 6.1.0.35
IBM HTTP Server 6.1.0.13
IBM HTTP Server 6.1.0.1
IBM HTTP Server 6.1.0
IBM eDiscovery Analyzer 2.2
IBM CommonStore for Lotus Domino 8.4
IBM CICS Transaction Gateway 8.0
IBM CICS Transaction Gateway 7.2
IBM AIX 7.1
IBM AIX 6.1
IBM AIX 5.3
HP Version Control Repository Manager 2.1.1 .730
HP Version Control Repository Manager 6.2.0.860
HP Version Control Repository Manager 6.1.0.841
HP Version Control Repository Manager 6.0.0.840
HP Version Control Repository Manager 2.2.2.835
HP Version Control Repository Manager 2.2.1.830
HP Version Control Repository Manager 2.2.0.820
HP Version Control Repository Manager 2.1.9.790
HP Version Control Repository Manager 2.1.8.780
HP Version Control Repository Manager 2.1.7.770
HP Version Control Repository Manager 2.1.5.760
HP Version Control Repository Manager 2.1.4.750
HP Version Control Repository Manager 2.1.3.740
HP Version Control Repository Manager 2.1.10.800
HP Version Control Agent 2.1.5
HP Version Control Agent 2.1.4
HP Version Control Agent 6.1.0.842
HP Version Control Agent 2.1.7.770
HP System Management Homepage 7.0
HP System Management Homepage 6.3
HP System Management Homepage 6.2
HP System Management Homepage 6.1
HP System Management Homepage 6.0
HP SSL for OpenVMS 1.4-453
HP SSL for OpenVMS 1.4
HP SiteScope 11.10
HP SiteScope 11.1
HP Performance Manager 9.00
HP Operations Agent 11.01
HP Operations Agent 11.0
HP Network Node Manager i 9.03
HP Network Node Manager i 9.02
HP Network Node Manager i 9.00
HP Network Automation 9.10
HP Network Automation 9.0
HP Integrated Lights Out 2 1.16
HP HP-UX 11.11
HP HP-UX B.11.31
HP HP-UX B.11.23
HP HP-UX B.11.11
HP HP-UX 11.31
HP HP System Management Homepage 6.1
HP Asset Manager 5.0
Gentoo Linux
Fortinet FortiGate 4.3.6
Fortinet FortiGate 4.3.5
Fortinet FortiClient 2.0
Debian Linux 6.0 sparc
Debian Linux 6.0 s/390
Debian Linux 6.0 powerpc
Debian Linux 6.0 mips
Debian Linux 6.0 ia-64
Debian Linux 6.0 ia-32
Debian Linux 6.0 arm
Debian Linux 6.0 amd64
Cosmicperl Directory Pro 10.0.3
Citrix Web Interface 5.1
Citrix Web Interface 5.0.2
Citrix Web Interface 5.0.1
Citrix Web Interface 4.5.1
Citrix Web Interface 5.4
Citrix Web Interface 5.3
Citrix Web Interface 5.0
Citrix Web Interface 4.6
Citrix Web Interface 4.0
Citrix Web Interface 3.0
Citrix Web Interface 2.0
Cisco Wireless Location Appliance 0
Cisco Unified Contact Center Enterprise 0
Cisco TelePresence Video Communication Server (VCS) 0
Cisco Nexus 7000 0
Cisco Nexus 3000 0
Cisco network Collector 0
Cisco Network Analysis Module 0
Cisco MDS 9000
Cisco IOS 0
Cisco Emergency Responder
Cisco ACE 4710 Appliance 0
CentOS CentOS 6
CentOS CentOS 5
Avaya Proactive Contact 5.0
Avaya Meeting Exchange 5.0 .0.52
Avaya Meeting Exchange 6.0
Avaya Meeting Exchange 5.2 SP2
Avaya Meeting Exchange 5.2 SP1
Avaya Meeting Exchange 5.2
Avaya Meeting Exchange 5.1 SP1
Avaya Meeting Exchange 5.1
Avaya Meeting Exchange 5.0 SP2
Avaya Meeting Exchange 5.0 SP1
Avaya Meeting Exchange 5.0
Avaya IQ 5.2
Avaya IQ 5.1.1
Avaya IQ 5.1
Avaya IQ 5
Avaya IP Office Application Server 8.1
Avaya IP Office Application Server 8.0
Avaya Communication Server 1000M Signaling Server 7.5
Avaya Communication Server 1000M Signaling Server 7.0
Avaya Communication Server 1000M Signaling Server 6.0
Avaya Communication Server 1000M 7.5
Avaya Communication Server 1000M 7.0
Avaya Communication Server 1000M 6.0
Avaya Communication Server 1000E Signaling Server 7.5
Avaya Communication Server 1000E Signaling Server 7.0
Avaya Communication Server 1000E Signaling Server 6.0
Avaya Communication Server 1000E 7.5
Avaya Communication Server 1000E 7.0
Avaya Communication Server 1000E 6.0
Avaya Aura System Platform 6.0.2
Avaya Aura System Platform 6.0.1
Avaya Aura System Platform 6.0 SP3
Avaya Aura System Platform 6.0 SP2
Avaya Aura System Platform 6.0
Avaya Aura System Platform 1.1
Avaya Aura System Manager 6.2
Avaya Aura System Manager 6.1.3
Avaya Aura System Manager 6.1.2
Avaya Aura System Manager 6.1.1
Avaya Aura System Manager 6.1 SP2
Avaya Aura System Manager 6.1 Sp1
Avaya Aura System Manager 6.1
Avaya Aura System Manager 6.0 SP1
Avaya Aura System Manager 6.0
Avaya Aura System Manager 5.2
Avaya Aura Session Manager 6.2.1
Avaya Aura Session Manager 6.1.3
Avaya Aura Session Manager 6.1.2
Avaya Aura Session Manager 6.1.1
Avaya Aura Session Manager 6.2
Avaya Aura Session Manager 6.1 SP2
Avaya Aura Session Manager 6.1 Sp1
Avaya Aura Session Manager 6.1
Avaya Aura Session Manager 6.0 SP1
Avaya Aura Session Manager 6.0
Avaya Aura Session Manager 5.2 SP2
Avaya Aura Session Manager 5.2 SP1
Avaya Aura Session Manager 5.2
Avaya Aura Presence Services 6.1.1
Avaya Aura Presence Services 6.1
Avaya Aura Presence Services 6.0
Avaya Aura Messaging 6.1
+ Avaya Communication Manager Server DEFINITY Server SI/CS
+ Avaya Communication Manager Server S8100
+ Avaya Communication Manager Server S8300
+ Avaya Communication Manager Server S8500
+ Avaya Communication Manager Server S8700
Avaya Aura Messaging 6.0.1
Avaya Aura Messaging 6.0
Avaya Aura Experience Portal 6.0
Avaya Aura Communication Manager Utility Services 6.2
Avaya Aura Communication Manager Utility Services 6.1
+ Avaya Communication Manager Server DEFINITY Server SI/CS
+ Avaya Communication Manager Server S8100
+ Avaya Communication Manager Server S8300
+ Avaya Communication Manager Server S8500
+ Avaya Communication Manager Server S8700
Avaya Aura Communication Manager Utility Services 6.0
Avaya Aura Communication Manager 6.0.1
Avaya Aura Communication Manager 6.0
Avaya Aura Application Server 5300 SIP Core 2.1
Avaya Aura Application Server 5300 SIP Core 2.0
Avaya Aura Application Enablement Services 5.2.1
Avaya Aura Application Enablement Services 3.1.6
Avaya Aura Application Enablement Services 6.1.1
Avaya Aura Application Enablement Services 6.1
Avaya Aura Application Enablement Services 5.2.3
Avaya Aura Application Enablement Services 5.2.2
Avaya Aura Application Enablement Services 5.2
Asterisk Asterisk Open Source 1.8.3.1
Apple Mac OS X 10.6.4
Apple Mac OS X 10.6.3
Apple Mac OS X 10.6.2
Apple Mac OS X 10.6.1
Apple Mac OS X 10.5.8
Apple Mac OS X 10.5.7
Apple Mac OS X 10.5.6
Apple Mac OS X 10.5.5
Apple Mac OS X 10.5.4
Apple Mac OS X 10.5.3
Apple Mac OS X 10.5.2
Apple Mac OS X 10.5.1
Apple Mac OS X 10.5
Apple Mac OS X 10.4.11
Apple Mac OS X 10.4.10
Apple Mac OS X 10.4.9
Apple Mac OS X 10.4.8
Apple Mac OS X 10.4.7
Apple Mac OS X 10.4.6
Apple Mac OS X 10.4.5
Apple Mac OS X 10.4.4
Apple Mac OS X 10.4.3
Apple Mac OS X 10.4.2
Apple Mac OS X 10.4.1
Apple Mac OS X 10.4
Apple Mac OS X 10.3.9
Apple Mac OS X 10.3.8
Apple Mac OS X 10.3.7
Apple Mac OS X 10.3.6
Apple Mac OS X 10.3.5
Apple Mac OS X 10.3.4
Apple Mac OS X 10.3.3
Apple Mac OS X 10.3.2
Apple Mac OS X 10.3.1
Apple Mac OS X 10.3
Apple Mac OS X 10.2.8
Apple Mac OS X 10.2.7
Apple Mac OS X 10.2.6
Apple Mac OS X 10.2.5
Apple Mac OS X 10.2.4
Apple Mac OS X 10.2.3
Apple Mac OS X 10.2.2
Apple Mac OS X 10.2.1
Apple Mac OS X 10.2
Apple Mac OS X 10.1.5
Apple Mac OS X 10.1.4
Apple Mac OS X 10.1.3
Apple Mac OS X 10.1.2
Apple Mac OS X 10.1.1
Apple Mac OS X 10.1
Apple Mac OS X 10.0.4
Apple Mac OS X 10.0.2
Apple Mac OS X 10.0.1
Apple Mac OS X 10.0 3
Apple Mac OS X 10.0
Apple Mac Os X 10.7.4
Apple Mac Os X 10.7.3
Apple Mac Os X 10.7.2
Apple Mac Os X 10.7.1
Apple Mac OS X 10.6
Apple Mac OS X 10.5
Apple iPod Touch 0
Apple iPhone 0
Apple iPad 0
Apple iOS 4.2.1
Apple iOS 4.0.2
Apple iOS 4.0.1
Apple iOS 3.2.2
Apple iOS 3.2.1
Apple iOS 5.1.1
Apple iOS 5.1
Apple iOS 5.0.1
Apple iOS 5
Apple iOS 4.3.5
Apple iOS 4.3.4
Apple iOS 4.3.3
Apple iOS 4.3.2
Apple iOS 4.3.1
Apple iOS 4.3
Apple iOS 4.2.9
Apple iOS 4.2.8
Apple iOS 4.2.7
Apple iOS 4.2.6
Apple iOS 4.2.5
Apple iOS 4.2.10
Apple iOS 4.2
Apple iOS 4.1
Apple iOS 4
Apple iOS 3.2
Apple iOS 3.1
Apple iOS 3.0
Apple iOS 2.1
Apple iOS 2.0
Apple Apple TV 5.0
Apple Apple TV 4.4
Apple Apple TV 4.3
Apple Apple TV 4.2
Apple Apple TV 4.1
Apple Apple TV 4.0
Apple Apple TV 2.1
Apple Apple TV 1.0
Not Vulnerable:

Discussion

OpenSSL CVE-2014-3566 Man In The Middle Information Disclosure Vulnerability

OpenSSL is prone to an information disclosure vulnerability.

An attacker can exploit this issue to perform man-in-the-middle attacks and obtain sensitive information. Successful exploits will lead to other attacks.

The following versions are vulnerable:

OpenSSL 0.9.8 prior to 0.9.8zc
OpenSSL 1.0.0 prior to 1.0.0o
OpenSSL 1.0.1 prior to 1.0.1j

Exploit / POC

OpenSSL CVE-2014-3566 Man In The Middle Information Disclosure Vulnerability

An attacker may use readily available tools to exploit this issue.

Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.

Solution / Fix

OpenSSL CVE-2014-3566 Man In The Middle Information Disclosure Vulnerability

Solution:
Updates are available. Please see the references or vendor advisory for more information.

References

OpenSSL CVE-2014-3566 Man In The Middle Information Disclosure Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report