Junglewise Threat Intelligence

CVE-2014-0160: OpenSSL Information Disclosure Vulnerability

CVE-2014-0160 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2022-05-04

Technologies: OpenSSL. Vendors: OpenSSL.

Executive brief

The TLS and DTLS implementations in OpenSSL 1.0.1 before 1.0.1g fail to properly handle Heartbeat Extension packets. This allows remote attackers to trigger a buffer over-read and obtain sensitive process memory, including private cryptographic keys and passwords, commonly known as the Heartbleed bug.

Affected products

  • OpenSSL OpenSSL 1.0.1 before 1.0.1g

Timeline

  • 2022-05-04: disclosed: NVD publication date provided in advisory.
  • exploited: Reported as exploited in the wild.

Related threats