Web Hack List

Other nomination

OpenSSL CVE-2014-0224

MITRE's record for CVE-2014-0224, the OpenSSL CCS Injection flaw. A man in the middle sends ChangeCipherSpec messages early in the handshake so both endpoints derive a zero-length master key, letting the attacker decrypt and modify traffic and hijack sessions between vulnerable OpenSSL peers.

Record

Published by
cve.mitre.org
Format
Advisory

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of cve.mitre.org, first published at the original source. Preserved copies are kept so the citation survives its host.