OpenSSL是OpenSSL团队开发的一个开源的能够实现安全套接层(SSL v2/v3)和安全传输层(TLS v1)协议的通用加密库,它支持多种加密算法,包括对称密码、哈希算法、安全散列算法等。 OpenSSL中存在安全漏洞,该漏洞源于程序没有正确限制ChangeCipherSpec消息的处理。攻击者可借助特制的TLS握手利用该漏洞实施中间人攻击,在OpenSSL-to-OpenSSL通信过程中使用零长度的主密钥,劫持会话或获取敏感消息。以下版本受到影响:OpenSSL 0.9.8y及之前的版本,1.0
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | This script is designed for detection of vulnerable servers (CVE-2014-0224.) in a wide range of configurations. It attempts to negotiate using each affected protocol version (SSLv3, TLSv1, TLSv1.1, and TLSv1.2) advertising a comprehensive set of ciphers. | https://github.com/Tripwire/OpenSSL-CCS-Inject-Test | POC Details |
| 2 | None | https://github.com/iph0n3/CVE-2014-0224 | POC Details |
| 3 | Used for evaluating hosts for CVE-2014-0224 | https://github.com/droptables/ccs-eval | POC Details |
| 4 | None | https://github.com/ssllabs/openssl-ccs-cve-2014-0224 | POC Details |
| 5 | None | https://github.com/secretnonempty/CVE-2014-0224 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2014-3969 | Xen 权限许可和访问控制漏洞 | |
| CVE-2014-2051 | OwnCloud Server 代码注入漏洞 | |
| CVE-2013-0304 | OwnCloud Server 安全绕过漏洞 | |
| CVE-2013-0302 | OwnCloud Server 未明远程信息泄露漏洞 | |
| CVE-2014-3976 | A10 Networks Advanced Core Operating System 缓冲区溢出漏洞 | |
| CVE-2014-3975 | AuraCMS 绝对路径遍历漏洞 | |
| CVE-2014-3974 | AuraCMS 跨站脚本漏洞 | |
| CVE-2014-3973 | FrontAccounting SQL注入漏洞 | |
| CVE-2014-3940 | Linux kernel 拒绝服务漏洞 | |
| CVE-2014-3917 | Linux kernel 安全漏洞 | |
| CVE-2014-3912 | Samsung iPOLiS Device Manager 基于栈的缓冲区溢出漏洞 | |
| CVE-2014-3878 | Ipswitch IMail Server 跨站脚本漏洞 | |
| CVE-2014-2577 | Bottomline Technologies Transform Foundation Server 跨站脚本漏洞 | |
| CVE-2014-1998 | Nippon Institute of Agroinformatics SOY CMS 跨站脚本漏洞 | |
| CVE-2014-1997 | ATEN CN8000 拒绝服务漏洞 | |
| CVE-2014-0195 | OpenSSL 缓冲区错误漏洞 | |
| CVE-2014-3968 | Xen 拒绝服务漏洞 | |
| CVE-2014-3967 | Xen 拒绝服务漏洞 | |
| CVE-2014-3469 | GNU Libtasn1 代码问题漏洞 | |
| CVE-2014-3468 | GNU Libtasn1 数字错误漏洞 |
Showing top 20 of 30 CVEs. View all on vendor page → →
No comments yet