Vulnerability record · CVE-2014-3505 · published 13 August 2014
CVE-2014-3505: OpenSSL DTLS double free allows remote denial of service
OOpenssl · Openssl
OpenSSL's DTLS implementation in d1_both.c contains a double free that is triggered when crafted DTLS packets cause an error condition. A remote attacker can crash the application, causing a denial of service. The flaw affects OpenSSL 0.9.8 before 0.9.8zb, 1.0.0 before 1.0.0n, and 1.0.1 before 1.0.1i.
Description
Double free vulnerability in d1_both.c in the DTLS implementation in OpenSSL 0.9.8 before 0.9.8zb, 1.0.0 before 1.0.0n, and 1.0.1 before 1.0.1i allows remote attackers to cause a denial of service (application crash) via crafted DTLS packets that trigger an error condition.
AV:N/AC:L/Au:N/C:N/I:N/A:P
Automated analysis
medium priorityThe flaw is remotely triggerable without authentication but only causes denial of service, and no known exploitation is documented.
What it is
OpenSSL's DTLS implementation in d1_both.c contains a double free that is triggered when crafted DTLS packets cause an error condition. A remote attacker can crash the application, causing a denial of service. The flaw affects OpenSSL 0.9.8 before 0.9.8zb, 1.0.0 before 1.0.0n, and 1.0.1 before 1.0.1i.
Impact
An attacker can cause a denial of service by crashing the application that uses the vulnerable OpenSSL DTLS code. There is no reported loss of confidentiality or integrity; the CVSS vector shows availability impact only.
Attack surface
The vulnerability is reachable over the network via DTLS packets, as indicated by the AV:N vector. No authentication or user interaction is required according to the CVSS vector (Au:N) and the description of remote attackers.
Exploitation
The CVE is not listed in CISA KEV, and no reference tags indicate public exploit code. EPSS gives a 30-day exploitation probability of 0.46124 (98.755th percentile), suggesting high predicted activity despite the absence of known exploitation.
What to do
- Upgrade OpenSSL to 0.9.8zb, 1.0.0n, 1.0.1i or later.
- Apply vendor security updates for affected operating systems and distributions.
- If DTLS is not required, disable or block DTLS services to reduce exposure.
- Monitor for and restart crashed DTLS-dependent services to limit downtime.
Detection
- Monitor application and system logs for crashes or abnormal terminations in services using OpenSSL DTLS.
- Use network monitoring to detect malformed or unusual DTLS packet patterns targeting DTLS endpoints.
- Track OpenSSL versions in use and verify patched builds are deployed.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2014-3505 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-3505), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.