CVE-2013-6449

    Dashboard / Vulnerabilities / CVE-2013-6449

    CVE-2013-6449

    Published: 23 Dec 2013Last Modified: 16 Apr 2026

    Summary:

    Details: The ssl_get_algorithm2 function in ssl/s3_lib.c in OpenSSL before 1.0.2 obtains a certain version number from an incorrect data structure, which allows remote attackers to cause a denial of service (daemon crash) via crafted traffic from a TLS 1.2 client.

    References: http://rhn.redhat.com/errata/RHSA-2014-0015.html, http://rhn.redhat.com/errata/RHSA-2014-0041.html, http://security.gentoo.org/glsa/glsa-201412-39.xml, http://www.debian.org/security/2014/dsa-2833, http://www.ubuntu.com/usn/USN-2079-1, http://www.vmware.com/security/advisories/VMSA-2014-0012.html, https://bugzilla.redhat.com/show_bug.cgi?id=1045363, http://git.openssl.org/gitweb/?p=openssl.git%3Ba=commit%3Bh=ca989269a2876bae79393bd54c3e72d49975fc75, http://lists.fedoraproject.org/pipermail/package-announce/2013-December/124833.html, http://lists.fedoraproject.org/pipermail/package-announce/2013-December/124854.html, http://lists.fedoraproject.org/pipermail/package-announce/2013-December/124858.html, http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136470.html, http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136473.html, http://lists.opensuse.org/opensuse-updates/2014-01/msg00006.html, http://lists.opensuse.org/opensuse-updates/2014-01/msg00009.html, http://lists.opensuse.org/opensuse-updates/2014-01/msg00012.html, http://lists.opensuse.org/opensuse-updates/2014-01/msg00031.html, http://rt.openssl.org/Ticket/Display.html?id=3200&user=guest&pass=guest, http://seclists.org/fulldisclosure/2014/Dec/23, http://www-01.ibm.com/support/docview.wss?uid=isg400001841, http://www-01.ibm.com/support/docview.wss?uid=isg400001843, http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html, http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html, http://www.securityfocus.com/archive/1/534161/100/0/threaded, http://www.securityfocus.com/bid/64530, http://www.securitytracker.com/id/1029548, https://issues.apache.org/jira/browse/TS-2355

    Affected packages

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High