Vulnerability Description
The DTLS retransmission implementation in OpenSSL 1.0.0 before 1.0.0l and 1.0.1 before 1.0.1f does not properly maintain data structures for digest and encryption contexts, which might allow man-in-the-middle attackers to trigger the use of a different context and cause a denial of service (application crash) by interfering with packet delivery, related to ssl/d1_both.c and ssl/t1_enc.c.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openssl | Openssl | 1.0.0 |
Related Weaknesses (CWE)
References
- http://git.openssl.org/gitweb/?p=openssl.git%3Ba=commit%3Bh=34628967f1e65dc8f34e
- http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136470.htm
- http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136473.htm
- http://lists.opensuse.org/opensuse-updates/2014-01/msg00031.html
- http://lists.opensuse.org/opensuse-updates/2014-01/msg00032.html
- http://rhn.redhat.com/errata/RHSA-2014-0015.html
- http://seclists.org/fulldisclosure/2014/Dec/23
- http://security.gentoo.org/glsa/glsa-201412-39.xml
- http://www-01.ibm.com/support/docview.wss?uid=isg400001841
- http://www-01.ibm.com/support/docview.wss?uid=isg400001843
- http://www.debian.org/security/2014/dsa-2833
- http://www.openssl.org/news/vulnerabilities.html
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html
- http://www.securityfocus.com/archive/1/534161/100/0/threaded
FAQ
What is CVE-2013-6450?
CVE-2013-6450 is a vulnerability with a CVSS score of 5.8 (MEDIUM). The DTLS retransmission implementation in OpenSSL 1.0.0 before 1.0.0l and 1.0.1 before 1.0.1f does not properly maintain data structures for digest and encryption contexts, which might allow man-in-th...
How severe is CVE-2013-6450?
CVE-2013-6450 has been rated MEDIUM with a CVSS base score of 5.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-6450?
Check the references section above for vendor advisories and patch information. Affected products include: Openssl Openssl.