Heartbleed (CVE-2014-0160)

E792089

Heartbleed (CVE-2014-0160) is a critical security bug in the OpenSSL cryptographic library that allowed attackers to read sensitive data from the memory of affected servers, compromising encryption keys, passwords, and other private information.

All labels observed (4)

Label Occurrences
CVE-2014-0160 1
Heartbleed 1
Heartbleed (CVE-2014-0160) canonical 1

How this entity was disambiguated

Statements (53)

Predicate Object
instanceOf OpenSSL vulnerability ⓘ
information disclosure vulnerability ⓘ
security bug ⓘ
software vulnerability ⓘ
affectedRange OpenSSL 1.0.1 through 1.0.1f ⓘ
linked to: OpenSSL

OpenSSL 1.0.2-beta1 ⓘ
linked to: OpenSSL
affectsComponent OpenSSL TLS/DTLS implementation ⓘ
linked to: OpenSSL
affectsProtocol DTLS ⓘ
TLS ⓘ
affectsSoftware OpenSSL ⓘ
allows disclosure of other sensitive data ⓘ
disclosure of passwords ⓘ
disclosure of private keys ⓘ
disclosure of session cookies ⓘ
reading process memory of affected client ⓘ
reading process memory of affected server ⓘ
attackComplexity low ⓘ
attackPrerequisite use of vulnerable OpenSSL version ⓘ
attackVector crafted TLS heartbeat request ⓘ
CVEID CVE-2014-0160 ⓘ
CVSSv2BaseScore 5.0 ⓘ
CVSSv2ExploitabilitySubscore 10.0 ⓘ
CVSSv2ImpactSubscore 2.9 ⓘ
CWEID CWE-125 ⓘ
linked to: CWE
CWEName Out-of-bounds Read ⓘ
dateDisclosed 2014-04-07 ⓘ
datePubliclyReported 2014-04-07 ⓘ
discoveredBy Codenomicon security team ⓘ
Neel Mehta ⓘ
discoveredByOrganization Codenomicon ⓘ
Google Security Team ⓘ
exploitation remote ⓘ
fixedBy disabling TLS heartbeat extension ⓘ
fixedInVersion OpenSSL 1.0.1g ⓘ
linked to: OpenSSL
hasLogo bleeding heart logo ⓘ
hasNameOrigin named by Codenomicon ⓘ
impacts VPN servers ⓘ
confidentiality ⓘ
email servers ⓘ
embedded devices using OpenSSL ⓘ
encryption keys ⓘ
user credentials ⓘ
web servers ⓘ
introducedInVersion OpenSSL 1.0.1 ⓘ
linked to: OpenSSL

OpenSSL 1.0.1-beta1 ⓘ
linked to: OpenSSL

OpenSSL 1.0.2-beta1 ⓘ
linked to: OpenSSL
notableConsequence necessitated mass revocation and reissue of TLS certificates ⓘ
prompted large-scale password resets on many websites ⓘ
requiresAuthentication false ⓘ
standardIdentifier CVE-2014-0160 ⓘ
vulnerabilityType bounds-checking error ⓘ
buffer over-read ⓘ
input validation error ⓘ

How these facts were elicited

Referenced by (4)

Full triples — surface form annotated when it differs from this entity's canonical label.

OpenSSL → notableVulnerability → Heartbleed (CVE-2014-0160) ⓘ
TLS heartbeat extension → associatedVulnerability → Heartbleed ⓘ
linked to: Heartbleed (CVE-2014-0160)
TLS heartbeat extension → notableImplementationBug → OpenSSL Heartbleed bug ⓘ
linked to: Heartbleed (CVE-2014-0160)
Heartbleed → standardIdentifier → CVE-2014-0160 ⓘ
subject linked to: Heartbleed (CVE-2014-0160)
linked to: Heartbleed (CVE-2014-0160)