Web Hack List

Collected research

OpenSSL CVE-2014-0224

CVE - CVE-2014-0224

MITRE's record for CVE-2014-0224, the OpenSSL CCS Injection flaw. A man in the middle sends ChangeCipherSpec messages early in the handshake so both endpoints derive a zero-length master key, letting the attacker decrypt and modify traffic and hijack sessions between vulnerable OpenSSL peers.

Record

Document
CVE - CVE-2014-0224
Published by
cve.mitre.org
Format
Advisory
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of cve.mitre.org, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .