LOW · 3.4

CVE-2014-3566

The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padd...

Vulnerability Description

The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.

CVSS Score

3.4

LOW

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
LOW
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
RedhatEnterprise Linux5
RedhatEnterprise Linux Desktop6.0
RedhatEnterprise Linux Desktop Supplementary5.0
RedhatEnterprise Linux Server6.0
RedhatEnterprise Linux Server Supplementary5.0
RedhatEnterprise Linux Workstation6.0
RedhatEnterprise Linux Workstation Supplementary6.0
IbmAix5.3
AppleMac Os X<= 10.10.1
MageiaMageia3.0
NovellSuse Linux Enterprise Desktop9.0
NovellSuse Linux Enterprise Software Development Kit11.0
NovellSuse Linux Enterprise Server11.0
OpensuseOpensuse12.3
FedoraprojectFedora19
OpensslOpenssl0.9.8
IbmVios2.2.0.10
NetbsdNetbsd5.1
DebianDebian Linux7.0
OracleDatabase11.2.0.4

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-3566?

CVE-2014-3566 is a vulnerability with a CVSS score of 3.4 (LOW). The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padd...

How severe is CVE-2014-3566?

CVE-2014-3566 has been rated LOW with a CVSS base score of 3.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-3566?

Check the references section above for vendor advisories and patch information. Affected products include: Redhat Enterprise Linux, Redhat Enterprise Linux Desktop, Redhat Enterprise Linux Desktop Supplementary, Redhat Enterprise Linux Server, Redhat Enterprise Linux Server Supplementary.