CVE-2014-3508 is an information disclosure vulnerability affecting OpenSSL versions 0.9.8 before 0.9.8zb, 1.0.0 before 1.0.0n, and 1.0.1 before 1.0.1i. The flaw in the OBJ_obj2txt function, when pretty printing is used, fails to ensure null termination, allowing attackers to read sensitive data from process stack memory. This vulnerability has a CVSS score of 4.3, indicating a medium attack complexity and potential for partial confidentiality impact, but no integrity or availability impact. There is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or KEV listing, though it has received some community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.9.8CPE matchmatch criteria | cpe:2.3:a:openssl:openssl:0.9.8:*:*:*:*:*:*:* | ||
0.9.8aCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:0.9.8a:*:*:*:*:*:*:* | ||
0.9.8bCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:0.9.8b:*:*:*:*:*:*:* | ||
0.9.8cCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:0.9.8c:*:*:*:*:*:*:* | ||
0.9.8dCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:0.9.8d:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.