← Vulnerability feed

Vulnerability record · CVE-2014-3506 · published 13 August 2014

CVE-2014-3506: OpenSSL DTLS handshake memory exhaustion denial of service

OOpenssl · Openssl

OpenSSL's DTLS implementation in d1_both.c fails to properly validate length values in crafted handshake messages, causing memory allocations proportional to attacker-supplied large lengths. A remote unauthenticated attacker can exhaust process memory and cause a denial of service. The flaw affects OpenSSL 0.9.8 before 0.9.8zb, 1.0.0 before 1.0.0n, and 1.0.1 before 1.0.1i.

5.0 CVSS 2.0 Medium EPSS 46% · top 1.2% CWE-399 · CWE-399
5.0CVSS 2.0 base score
46%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
108References
17 Jun 2026Last modified by NVD

Description

d1_both.c in the DTLS implementation in OpenSSL 0.9.8 before 0.9.8zb, 1.0.0 before 1.0.0n, and 1.0.1 before 1.0.1i allows remote attackers to cause a denial of service (memory consumption) via crafted DTLS handshake messages that trigger memory allocations corresponding to large length values.

AV:N/AC:L/Au:N/C:N/I:N/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityRemote unauthenticated memory-exhaustion DoS with a high EPSS percentile, though no KEV listing or confirmed public exploit in the record.

What it is

OpenSSL's DTLS implementation in d1_both.c fails to properly validate length values in crafted handshake messages, causing memory allocations proportional to attacker-supplied large lengths. A remote unauthenticated attacker can exhaust process memory and cause a denial of service. The flaw affects OpenSSL 0.9.8 before 0.9.8zb, 1.0.0 before 1.0.0n, and 1.0.1 before 1.0.1i.

Impact

An attacker can force excessive memory allocation in the affected OpenSSL process, leading to memory exhaustion and denial of service. There is no confidentiality or integrity impact per the CVSS vector.

Attack surface

Reachable over the network via DTLS handshake messages; the CVSS vector AV:N/AC:L/Au:N indicates no authentication is required and no user interaction is needed. Any service exposing DTLS (for example, DTLS-based TLS endpoints) is potentially reachable.

Exploitation

Not listed in CISA KEV and no ransomware associations are documented. EPSS is 0.46124 (98.755th percentile), indicating a high modeled likelihood of exploitation activity, but the record contains no reference tags confirming public exploit code.

What to do

  • Upgrade OpenSSL to 0.9.8zb, 1.0.0n, 1.0.1i or later, or apply the vendor patch for your distribution.
  • Apply the referenced vendor errata (Red Hat RHSA-2014-1256/RHSA-2014-1297, Oracle ELSA-2014-1052/1053, IBM AIX, NetBSD, openSUSE) where OpenSSL is bundled.
  • If DTLS is not required, disable DTLS listeners and restrict UDP exposure to trusted networks.
  • Monitor and cap memory usage for processes that terminate DTLS, and restart them on abnormal growth.
  • Inventory all OpenSSL deployments, including embedded and third-party components, to confirm patched versions.

Detection

  • Monitor DTLS endpoints for abnormal memory growth or process restarts that correlate with inbound handshake traffic.
  • Inspect network traffic for DTLS handshake messages carrying unusually large length values or repeated handshake retransmissions.
  • Alert on OpenSSL process crashes or OOM-killer events on hosts that terminate DTLS.
  • Track patch status of OpenSSL versions against the fixed releases 0.9.8zb, 1.0.0n and 1.0.1i.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2014-008.txt.asc
http://aix.software.ibm.com/aix/efixes/security/openssl_advisory10.asc
http://linux.oracle.com/errata/ELSA-2014-1052.html
http://linux.oracle.com/errata/ELSA-2014-1053.html
http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136470.html
http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136473.html
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.html
http://lists.opensuse.org/opensuse-updates/2014-08/msg00036.html
http://marc.info/?l=bugtraq&m=140853041709441&w=2
http://marc.info/?l=bugtraq&m=141077370928502&w=2
http://marc.info/?l=bugtraq&m=142660345230545&w=2
http://rhn.redhat.com/errata/RHSA-2014-1256.html
http://rhn.redhat.com/errata/RHSA-2014-1297.html
http://secunia.com/advisories/58962
http://secunia.com/advisories/59221
http://secunia.com/advisories/59700
http://secunia.com/advisories/59710
http://secunia.com/advisories/59743
http://secunia.com/advisories/59756
http://secunia.com/advisories/60022
http://secunia.com/advisories/60221
http://secunia.com/advisories/60493
http://secunia.com/advisories/60684
http://secunia.com/advisories/60687
http://secunia.com/advisories/60778
http://secunia.com/advisories/60803
http://secunia.com/advisories/60824
http://secunia.com/advisories/60917
http://secunia.com/advisories/60921
http://secunia.com/advisories/60938
http://secunia.com/advisories/61017
http://secunia.com/advisories/61040
http://secunia.com/advisories/61100
http://secunia.com/advisories/61184
http://secunia.com/advisories/61250
http://secunia.com/advisories/61775
http://secunia.com/advisories/61959
http://security.gentoo.org/glsa/glsa-201412-39.xml
http://support.f5.com/kb/en-us/solutions/public/15000/500/sol15573.html
http://www-01.ibm.com/support/docview.wss?uid=nas8N1020240

Track CVE-2014-3506 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2014-0160OpenSSL TLS/DTLS Heartbeat Extension Out-of-Bounds Read (Heartbleed)OpenSSL 1.0.1 before 1.0.1g mishandles Heartbeat Extension packets in its TLS and DTLS implementations, causing an out-of-bounds read of process memo…KEVEPSS 100%analysed10.0CVE-2009-3245Openssl improper input validation vulnerabilityOpenSSL before 0.9.8m does not check for a NULL return value from bn_wexpand function calls in (1) crypto/bn/bn_div.c, (2) crypto/bn/bn_gf2m.c, (3) c…EPSS 6.5%10.0CVE-2006-3738OpenSSL SSL_get_shared_ciphers buffer overflow via long cipher listOpenSSL versions before 0.9.7l and 0.9.8d contain a buffer overflow in the SSL_get_shared_ciphers function, triggered by a long list of ciphers. The …EPSS 49%analysed9.8CVE-2026-63073Openssl vulnerabilityIssue summary: OpenSSL CMP response validation passed an unexpected response sender distinguished name directly as the format string to `ERR_raise_da…EPSS 1.2%9.8CVE-2026-31789Openssl out-of-bounds write vulnerabilityIssue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platforms. Impact…EPSS 0.33%9.8CVE-2022-2274OpenSSL 3.0.4 RSA AVX512IFMA memory corruptionOpenSSL 3.0.4 introduced a bug in the RSA implementation for X86_64 CPUs supporting AVX512IFMA instructions, causing 2048-bit private key operations …EPSS 46%analysed9.8CVE-2021-3711OpenSSL SM2 decryption buffer overflowOpenSSL's SM2 decryption code miscalculates the output buffer size needed by EVP_PKEY_decrypt(), so the first sizing call can return a value smaller …EPSS 88%analysed9.8CVE-2016-6309OpenSSL 1.1.0a statem use-after-free on realloc in TLS session handlingOpenSSL 1.1.0a's statem/statem.c fails to account for memory-block movement after a realloc call, leaving a dangling pointer that can be used after f…EPSS 70%analysed

Source: NIST National Vulnerability Database (record CVE-2014-3506), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.