CVE-2014-5139
MEDIUM 4.3EPSS 16.2%
The ssl_set_client_disabled function in t1_lib.c in OpenSSL 1.0.1 before 1.0.1i allows remote SSL servers to cause a denial of service (NULL pointer dereference and client application crash) via a ServerHello message that includes an SRP ciphersuite without the required negotiation of that ciphersuite with the client.
- CVSS v2.0
- 4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P - EPSS
- 16.22% chance of exploitation in the next 30 days, 97th percentile
- Published
- 2014-08-13
- Updated
- 2024-08-06
Proof-of-concept exploits (2)
- uthrasri/CVE-2014-51390★ · 2023-11-09
- uthrasri/G2.5_openssl_CVE-2014-51390★ · 2023-11-09