PoC Index

CVE-2014-5139

MEDIUM 4.3EPSS 16.2%

The ssl_set_client_disabled function in t1_lib.c in OpenSSL 1.0.1 before 1.0.1i allows remote SSL servers to cause a denial of service (NULL pointer dereference and client application crash) via a ServerHello message that includes an SRP ciphersuite without the required negotiation of that ciphersuite with the client.

CVSS v2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
EPSS
16.22% chance of exploitation in the next 30 days, 97th percentile
Published
2014-08-13
Updated
2024-08-06

Proof-of-concept exploits (2)

References

Related