CVE-2014-2899
Gentoo Linux Security Advisory 201612-53
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
wolfSSL CyaSSL before 2.9.4 allows remote attackers to cause a denial of service (NULL pointer dereference) via (1) a request for the peer certificate when a certificate parsing failure occurs or (2) a client_key_exchange message when the ephemeral key is not found.
wolfSSL CyaSSL anterior a 2.9.4 permite a atacantes remotos causar una denegación de servicio (referencia a puntero nulo) a través de (1) una solicitud para el certificado de par cuando sucede un fallo de análisis sintáctico de certificado o (2) un mensaje client_key_exchange cuando la clave efímera no se encuentra.
Multiple vulnerabilities have been found in CyaSSL, the worst of which may allow attackers to execute arbitrary code. Versions 2.9.4 are affected.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-04-18 CVE Reserved
- 2014-04-22 CVE Published
- 2024-08-06 CVE Updated
- 2025-07-19 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://seclists.org/oss-sec/2014/q2/126 | Mailing List |
|
http://seclists.org/oss-sec/2014/q2/130 | Mailing List |
|
http://www.securityfocus.com/bid/66780 | Vdb Entry | |
http://www.wolfssl.com/yaSSL/Docs-cyassl-changelog.html | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/57743 | 2017-07-01 | |
http://www.wolfssl.com/yaSSL/Blog/Entries/2014/4/11_wolfSSL_Security_Advisory__April_9%2C_2014.html | 2017-07-01 | |
https://security.gentoo.org/glsa/201612-53 | 2017-07-01 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Yassl Search vendor "Yassl" | Cyassl Search vendor "Yassl" for product "Cyassl" | <= 2.9.0 Search vendor "Yassl" for product "Cyassl" and version " <= 2.9.0" | - |
Affected
| ||||||
Yassl Search vendor "Yassl" | Cyassl Search vendor "Yassl" for product "Cyassl" | 0.2.0 Search vendor "Yassl" for product "Cyassl" and version "0.2.0" | - |
Affected
| ||||||
Yassl Search vendor "Yassl" | Cyassl Search vendor "Yassl" for product "Cyassl" | 0.3.0 Search vendor "Yassl" for product "Cyassl" and version "0.3.0" | - |
Affected
| ||||||
Yassl Search vendor "Yassl" | Cyassl Search vendor "Yassl" for product "Cyassl" | 0.4.0 Search vendor "Yassl" for product "Cyassl" and version "0.4.0" | - |
Affected
| ||||||
Yassl Search vendor "Yassl" | Cyassl Search vendor "Yassl" for product "Cyassl" | 0.5.0 Search vendor "Yassl" for product "Cyassl" and version "0.5.0" | - |
Affected
| ||||||
Yassl Search vendor "Yassl" | Cyassl Search vendor "Yassl" for product "Cyassl" | 0.5.5 Search vendor "Yassl" for product "Cyassl" and version "0.5.5" | - |
Affected
| ||||||
Yassl Search vendor "Yassl" | Cyassl Search vendor "Yassl" for product "Cyassl" | 0.6.0 Search vendor "Yassl" for product "Cyassl" and version "0.6.0" | - |
Affected
| ||||||
Yassl Search vendor "Yassl" | Cyassl Search vendor "Yassl" for product "Cyassl" | 0.6.2 Search vendor "Yassl" for product "Cyassl" and version "0.6.2" | - |
Affected
| ||||||
Yassl Search vendor "Yassl" | Cyassl Search vendor "Yassl" for product "Cyassl" | 0.6.3 Search vendor "Yassl" for product "Cyassl" and version "0.6.3" | - |
Affected
| ||||||
Yassl Search vendor "Yassl" | Cyassl Search vendor "Yassl" for product "Cyassl" | 0.8.0 Search vendor "Yassl" for product "Cyassl" and version "0.8.0" | - |
Affected
| ||||||
Yassl Search vendor "Yassl" | Cyassl Search vendor "Yassl" for product "Cyassl" | 0.9.0 Search vendor "Yassl" for product "Cyassl" and version "0.9.0" | - |
Affected
| ||||||
Yassl Search vendor "Yassl" | Cyassl Search vendor "Yassl" for product "Cyassl" | 0.9.6 Search vendor "Yassl" for product "Cyassl" and version "0.9.6" | - |
Affected
| ||||||
Yassl Search vendor "Yassl" | Cyassl Search vendor "Yassl" for product "Cyassl" | 0.9.8 Search vendor "Yassl" for product "Cyassl" and version "0.9.8" | - |
Affected
| ||||||
Yassl Search vendor "Yassl" | Cyassl Search vendor "Yassl" for product "Cyassl" | 0.9.9 Search vendor "Yassl" for product "Cyassl" and version "0.9.9" | - |
Affected
| ||||||
Yassl Search vendor "Yassl" | Cyassl Search vendor "Yassl" for product "Cyassl" | 1.0.0 Search vendor "Yassl" for product "Cyassl" and version "1.0.0" | rc1 |
Affected
| ||||||
Yassl Search vendor "Yassl" | Cyassl Search vendor "Yassl" for product "Cyassl" | 1.0.0 Search vendor "Yassl" for product "Cyassl" and version "1.0.0" | rc2 |
Affected
| ||||||
Yassl Search vendor "Yassl" | Cyassl Search vendor "Yassl" for product "Cyassl" | 1.0.0 Search vendor "Yassl" for product "Cyassl" and version "1.0.0" | rc3 |
Affected
| ||||||
Yassl Search vendor "Yassl" | Cyassl Search vendor "Yassl" for product "Cyassl" | 1.0.2 Search vendor "Yassl" for product "Cyassl" and version "1.0.2" | - |
Affected
| ||||||
Yassl Search vendor "Yassl" | Cyassl Search vendor "Yassl" for product "Cyassl" | 1.0.3 Search vendor "Yassl" for product "Cyassl" and version "1.0.3" | - |
Affected
| ||||||
Yassl Search vendor "Yassl" | Cyassl Search vendor "Yassl" for product "Cyassl" | 1.0.6 Search vendor "Yassl" for product "Cyassl" and version "1.0.6" | - |
Affected
| ||||||
Yassl Search vendor "Yassl" | Cyassl Search vendor "Yassl" for product "Cyassl" | 1.1.0 Search vendor "Yassl" for product "Cyassl" and version "1.1.0" | - |
Affected
| ||||||
Yassl Search vendor "Yassl" | Cyassl Search vendor "Yassl" for product "Cyassl" | 1.2.0 Search vendor "Yassl" for product "Cyassl" and version "1.2.0" | - |
Affected
| ||||||
Yassl Search vendor "Yassl" | Cyassl Search vendor "Yassl" for product "Cyassl" | 1.3.0 Search vendor "Yassl" for product "Cyassl" and version "1.3.0" | - |
Affected
| ||||||
Yassl Search vendor "Yassl" | Cyassl Search vendor "Yassl" for product "Cyassl" | 1.4.0 Search vendor "Yassl" for product "Cyassl" and version "1.4.0" | - |
Affected
| ||||||
Yassl Search vendor "Yassl" | Cyassl Search vendor "Yassl" for product "Cyassl" | 1.5.0 Search vendor "Yassl" for product "Cyassl" and version "1.5.0" | - |
Affected
| ||||||
Yassl Search vendor "Yassl" | Cyassl Search vendor "Yassl" for product "Cyassl" | 1.5.4 Search vendor "Yassl" for product "Cyassl" and version "1.5.4" | - |
Affected
| ||||||
Yassl Search vendor "Yassl" | Cyassl Search vendor "Yassl" for product "Cyassl" | 1.5.6 Search vendor "Yassl" for product "Cyassl" and version "1.5.6" | - |
Affected
| ||||||
Yassl Search vendor "Yassl" | Cyassl Search vendor "Yassl" for product "Cyassl" | 1.6.0 Search vendor "Yassl" for product "Cyassl" and version "1.6.0" | - |
Affected
| ||||||
Yassl Search vendor "Yassl" | Cyassl Search vendor "Yassl" for product "Cyassl" | 1.6.5 Search vendor "Yassl" for product "Cyassl" and version "1.6.5" | - |
Affected
| ||||||
Yassl Search vendor "Yassl" | Cyassl Search vendor "Yassl" for product "Cyassl" | 1.8.0 Search vendor "Yassl" for product "Cyassl" and version "1.8.0" | - |
Affected
| ||||||
Yassl Search vendor "Yassl" | Cyassl Search vendor "Yassl" for product "Cyassl" | 1.9.0 Search vendor "Yassl" for product "Cyassl" and version "1.9.0" | - |
Affected
| ||||||
Yassl Search vendor "Yassl" | Cyassl Search vendor "Yassl" for product "Cyassl" | 2.0.0 Search vendor "Yassl" for product "Cyassl" and version "2.0.0" | rc1 |
Affected
| ||||||
Yassl Search vendor "Yassl" | Cyassl Search vendor "Yassl" for product "Cyassl" | 2.0.0 Search vendor "Yassl" for product "Cyassl" and version "2.0.0" | rc2 |
Affected
| ||||||
Yassl Search vendor "Yassl" | Cyassl Search vendor "Yassl" for product "Cyassl" | 2.0.0 Search vendor "Yassl" for product "Cyassl" and version "2.0.0" | rc3 |
Affected
| ||||||
Yassl Search vendor "Yassl" | Cyassl Search vendor "Yassl" for product "Cyassl" | 2.0.2 Search vendor "Yassl" for product "Cyassl" and version "2.0.2" | - |
Affected
| ||||||
Yassl Search vendor "Yassl" | Cyassl Search vendor "Yassl" for product "Cyassl" | 2.0.6 Search vendor "Yassl" for product "Cyassl" and version "2.0.6" | - |
Affected
| ||||||
Yassl Search vendor "Yassl" | Cyassl Search vendor "Yassl" for product "Cyassl" | 2.0.8 Search vendor "Yassl" for product "Cyassl" and version "2.0.8" | - |
Affected
| ||||||
Yassl Search vendor "Yassl" | Cyassl Search vendor "Yassl" for product "Cyassl" | 2.2.0 Search vendor "Yassl" for product "Cyassl" and version "2.2.0" | - |
Affected
| ||||||
Yassl Search vendor "Yassl" | Cyassl Search vendor "Yassl" for product "Cyassl" | 2.3.0 Search vendor "Yassl" for product "Cyassl" and version "2.3.0" | - |
Affected
| ||||||
Yassl Search vendor "Yassl" | Cyassl Search vendor "Yassl" for product "Cyassl" | 2.4.0 Search vendor "Yassl" for product "Cyassl" and version "2.4.0" | - |
Affected
| ||||||
Yassl Search vendor "Yassl" | Cyassl Search vendor "Yassl" for product "Cyassl" | 2.4.6 Search vendor "Yassl" for product "Cyassl" and version "2.4.6" | - |
Affected
| ||||||
Yassl Search vendor "Yassl" | Cyassl Search vendor "Yassl" for product "Cyassl" | 2.5.0 Search vendor "Yassl" for product "Cyassl" and version "2.5.0" | - |
Affected
| ||||||
Yassl Search vendor "Yassl" | Cyassl Search vendor "Yassl" for product "Cyassl" | 2.6.0 Search vendor "Yassl" for product "Cyassl" and version "2.6.0" | - |
Affected
| ||||||
Yassl Search vendor "Yassl" | Cyassl Search vendor "Yassl" for product "Cyassl" | 2.7.0 Search vendor "Yassl" for product "Cyassl" and version "2.7.0" | - |
Affected
| ||||||
Yassl Search vendor "Yassl" | Cyassl Search vendor "Yassl" for product "Cyassl" | 2.8.0 Search vendor "Yassl" for product "Cyassl" and version "2.8.0" | - |
Affected
|