CVE-2014-0160
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2014-0160 is a serious vulnerability affecting the TLS and DTLS implementations in OpenSSL 1.0.1 before 1.0.1g. This issue allows remote attackers to read sensitive information from process memory, including private keys, by exploiting a buffer over-read vulnerability in the Heartbeat Extension packets of OpenSSL. This bug, also known as the Heartbleed bug, arises due to improper handling of these packets at the d1_both.c and t1_lib.c files. The vulnerability can lead to significant data exposure and must be addressed promptly by updating OpenSSL to a patched version.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- OpenSSL
- Mitel MiCollab
- Mitel MiVoice
- Red Hat Enterprise Linux
- Debian
Affected Vendors
- The OpenSSL Project
- Debian
- Red Hat
- Fedora Project
- Siemens AG