CVE-2014-0198 is a denial-of-service vulnerability in OpenSSL versions 1.x through 1.0.1g, affecting products like Debian, Fedora, MariaDB, and SUSE. It stems from improper buffer pointer management during recursive calls when SSL_MODE_RELEASE_BUFFERS is enabled, leading to a NULL pointer dereference and application crash. This vulnerability has a CVSS score of 4.3, indicating a medium attack complexity and potential for partial availability impact. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), it has garnered significant community discussion and media coverage, suggesting awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.0.0, <= 1.0.1gCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* | ||
>= 10.0.0, < 10.0.13CPE matchmatch criteria | cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:* | ||
19CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:19:*:*:*:*:*:*:* | ||
20CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:20:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:6.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.