CVE-2014-3566

low
Published 2014-10-15 ยท Modified 2026-05-28
CVSS v3
3.4
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
4.4

Description

The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.

Predictions

Exploit likelihood
80%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Apple Security HT ยท View original โ†— ยท proprietary-no-redistribution
Full prose not cached โ€” VIR stores only structured fields (affected/fixed versions, references) for this source. Click "View original" above for the vendor's full advisory.

Exploits

Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.

Metasploit modules

SSL/TLS Version Detection
Source code queued for fetch โ€” refresh in a moment.

OS impact

fedora Fedora Affected 3 releases
VersionStatusFixed in
21 Affected โ€”
20 Affected โ€”
19 Affected โ€”
freebsd FreeBSD Affected 21 releases
VersionStatusFixed in
6.1.5 Affected โ€”
6.1.4 Affected โ€”
6.1.3 Affected โ€”
6.1.2 Affected โ€”
6.1.1 Affected โ€”
6.1 Affected โ€”
6.0.6 Affected โ€”
6.0.5 Affected โ€”
6.0.4 Affected โ€”
6.0.3 Affected โ€”
6.0.2 Affected โ€”
6.0.1 Affected โ€”
6.0 Affected โ€”
5.2.2 Affected โ€”
5.2.1 Affected โ€”
5.2 Affected โ€”
5.1.4 Affected โ€”
5.1.3 Affected โ€”
5.1.2 Affected โ€”
5.1.1 Affected โ€”
5.1 Affected โ€”
macos macOS Affected 1 release
VersionStatusFixed in
โ€” Affected โ€”
redhat Red Hat Affected 3 releases
VersionStatusFixed in
7.0 Affected โ€”
6.0 Affected โ€”
5 Affected โ€”
suse SUSE Affected 5 releases
VersionStatusFixed in
13.1 Affected โ€”
12.3 Affected โ€”
12.0 Affected โ€”
11.0 Affected โ€”
โ€” Affected โ€”
debian Debian Mixed 7 releases
VersionStatusFixed in
trixie Fixed 0
sid Fixed 0
forky Fixed 0
bullseye Fixed 0
bookworm Fixed 0
8.0 Affected โ€”
7.0 Affected โ€”

Application impact

VendorProductVersionsFixed
suse novellsuse_linux_enterprise_software_development_kit11.0
suse novellsuse_linux_enterprise_software_development_kit12.0
openssl opensslopenssl0.9.8
openssl opensslopenssl0.9.8a
openssl opensslopenssl0.9.8b
openssl opensslopenssl0.9.8c
openssl opensslopenssl0.9.8d
openssl opensslopenssl0.9.8e
openssl opensslopenssl0.9.8f
openssl opensslopenssl0.9.8g
openssl opensslopenssl0.9.8h
openssl opensslopenssl0.9.8i
openssl opensslopenssl0.9.8j
openssl opensslopenssl0.9.8k
openssl opensslopenssl0.9.8l
openssl opensslopenssl0.9.8m
openssl opensslopenssl0.9.8n
openssl opensslopenssl0.9.8o
openssl opensslopenssl0.9.8p
openssl opensslopenssl0.9.8q
openssl opensslopenssl0.9.8r
openssl opensslopenssl0.9.8s
openssl opensslopenssl0.9.8t
openssl opensslopenssl0.9.8u
openssl opensslopenssl0.9.8v
openssl opensslopenssl0.9.8w
openssl opensslopenssl0.9.8x
openssl opensslopenssl0.9.8y
openssl opensslopenssl0.9.8z
openssl opensslopenssl0.9.8za
openssl opensslopenssl0.9.8zb
openssl opensslopenssl1.0.0
openssl opensslopenssl1.0.0a
openssl opensslopenssl1.0.0b
openssl opensslopenssl1.0.0c
openssl opensslopenssl1.0.0d
openssl opensslopenssl1.0.0e
openssl opensslopenssl1.0.0f
openssl opensslopenssl1.0.0g
openssl opensslopenssl1.0.0h
openssl opensslopenssl1.0.0i
openssl opensslopenssl1.0.0j
openssl opensslopenssl1.0.0k
openssl opensslopenssl1.0.0l
openssl opensslopenssl1.0.0m
openssl opensslopenssl1.0.0n
openssl opensslopenssl1.0.1
openssl opensslopenssl1.0.1a
openssl opensslopenssl1.0.1b
openssl opensslopenssl1.0.1c
openssl opensslopenssl1.0.1d
openssl opensslopenssl1.0.1e
openssl opensslopenssl1.0.1f
openssl opensslopenssl1.0.1g
openssl opensslopenssl1.0.1h
openssl opensslopenssl1.0.1i
ibm ibmvios2.2.0.10
ibm ibmvios2.2.0.11
ibm ibmvios2.2.0.12
ibm ibmvios2.2.0.13
ibm ibmvios2.2.1.0
ibm ibmvios2.2.1.1
ibm ibmvios2.2.1.3
ibm ibmvios2.2.1.4
ibm ibmvios2.2.1.5
ibm ibmvios2.2.1.6
ibm ibmvios2.2.1.7
ibm ibmvios2.2.1.8
ibm ibmvios2.2.1.9
ibm ibmvios2.2.2.0
ibm ibmvios2.2.2.1
ibm ibmvios2.2.2.2
ibm ibmvios2.2.2.3
ibm ibmvios2.2.2.4
ibm ibmvios2.2.2.5
ibm ibmvios2.2.3.0
ibm ibmvios2.2.3.1
ibm ibmvios2.2.3.2
ibm ibmvios2.2.3.3
ibm ibmvios2.2.3.4
oracle oracledatabase11.2.0.4
oracle oracledatabase12.1.0.2

References

CWEs

CWE-310 CWE-329

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.