CVE-2014-0160
Find out more about CVE-2014-0160 from the MITRE CVE dictionary dictionary and NIST NVD.
Statement
This issue did not affect the versions of openssl as shipped with Red Hat Enterprise Linux 5, Red Hat Enterprise Linux 6.4 and earlier, Red Hat JBoss Enterprise Application Platform 5 and 6, and Red Hat JBoss Web Server 1 and 2. This issue does affect Red Hat Enterprise Linux 7 Beta, Red Hat Enterprise Linux 6.5, Red Hat Enterprise Virtualization Hypervisor 6.5, and Red Hat Storage 2.1, which provided openssl 1.0.1e. Errata have been released to correct this issue.
Additional information can be found in the Red Hat Knowledgebase article: https://access.redhat.com/site/announcements/781953
CVSS v2 metrics
| Base Score | 5 |
|---|---|
| Base Metrics | AV:N/AC:L/Au:N/C:P/I:N/A:N |
| Access Vector | Network |
| Access Complexity | Low |
| Authentication | None |
| Confidentiality Impact | Partial |
| Integrity Impact | None |
| Availability Impact | None |
Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).
Red Hat Security Errata
| Platform | Errata | Release Date |
|---|---|---|
| Red Hat Enterprise Linux 6 (openssl) | RHSA-2014:0376 | 2014-04-08 |
| Red Hat Storage Server 2.1 (openssl) | RHSA-2014:0377 | 2014-04-08 |
| RHEV Manager 3 (spice-client-msi) | RHSA-2014:0416 | 2014-04-17 |
| RHEV Hypervisor for RHEL-6 (rhev-hypervisor6) | RHSA-2014:0396 | 2014-04-10 |
| RHEV Hypervisor for RHEL-6 (rhev-hypervisor6) | RHSA-2014:0378 | 2014-04-08 |
Affected Packages State
| Platform | Package | State |
|---|---|---|
| Red Hat JBoss EAP 6 | openssl | Not affected |
| Red Hat JBoss EAP 5 | openssl | Not affected |
| Red Hat Enterprise Linux 7 | openssl098e | Not affected |
| Red Hat Enterprise Linux 7 | openssl | Not affected |
| Red Hat Enterprise Linux 6 | openssl098e | Not affected |
| Red Hat Enterprise Linux 5 | openssl | Not affected |
| Red Hat Enterprise Linux 5 | openssl097a | Not affected |
| RHEV Manager 3 | mingw-virt-viewer | Affected |
