Heartbleed (CVE-2014-0160)

E792089

Heartbleed (CVE-2014-0160) is a critical security bug in the OpenSSL cryptographic library that allowed attackers to read sensitive data from the memory of affected servers, compromising encryption keys, passwords, and other private information.

All labels observed (4)

Label Occurrences
CVE-2014-0160 1
Heartbleed 1
Heartbleed (CVE-2014-0160) canonical 1

How this entity was disambiguated

Statements (53)

Predicate Object
instanceOf OpenSSL vulnerability
information disclosure vulnerability
security bug
software vulnerability
affectedRange OpenSSL 1.0.1 through 1.0.1f
linked to: OpenSSL

OpenSSL 1.0.2-beta1
linked to: OpenSSL
affectsComponent OpenSSL TLS/DTLS implementation
linked to: OpenSSL
affectsProtocol DTLS
TLS
affectsSoftware OpenSSL
allows disclosure of other sensitive data
disclosure of passwords
disclosure of private keys
disclosure of session cookies
reading process memory of affected client
reading process memory of affected server
attackComplexity low
attackPrerequisite use of vulnerable OpenSSL version
attackVector crafted TLS heartbeat request
CVEID CVE-2014-0160
CVSSv2BaseScore 5.0
CVSSv2ExploitabilitySubscore 10.0
CVSSv2ImpactSubscore 2.9
CWEID CWE-125
linked to: CWE
CWEName Out-of-bounds Read
dateDisclosed 2014-04-07
datePubliclyReported 2014-04-07
discoveredBy Codenomicon security team
Neel Mehta
discoveredByOrganization Codenomicon
Google Security Team
exploitation remote
fixedBy disabling TLS heartbeat extension
fixedInVersion OpenSSL 1.0.1g
linked to: OpenSSL
hasLogo bleeding heart logo
hasNameOrigin named by Codenomicon
impacts VPN servers
confidentiality
email servers
embedded devices using OpenSSL
encryption keys
user credentials
web servers
introducedInVersion OpenSSL 1.0.1
linked to: OpenSSL

OpenSSL 1.0.1-beta1
linked to: OpenSSL

OpenSSL 1.0.2-beta1
linked to: OpenSSL
notableConsequence necessitated mass revocation and reissue of TLS certificates
prompted large-scale password resets on many websites
requiresAuthentication false
standardIdentifier CVE-2014-0160
vulnerabilityType bounds-checking error
buffer over-read
input validation error

How these facts were elicited

Referenced by (4)

Full triples — surface form annotated when it differs from this entity's canonical label.

OpenSSL notableVulnerability Heartbleed (CVE-2014-0160)
TLS heartbeat extension associatedVulnerability Heartbleed
linked to: Heartbleed (CVE-2014-0160)
TLS heartbeat extension notableImplementationBug OpenSSL Heartbleed bug
linked to: Heartbleed (CVE-2014-0160)
Heartbleed standardIdentifier CVE-2014-0160
subject linked to: Heartbleed (CVE-2014-0160)
linked to: Heartbleed (CVE-2014-0160)