View at Official suse advisory, NVD, CVE.org · CVE detail
Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.
CVE-2014-0195 severity moderate: SUSE including 197 source package names (compat-openssl098, libmysqlclient-devel-10.0.16-15.1, …), 465 product×package rows across 59 product lines (SUSE CaaS Platform 4.0, SUSE Enterprise Storage 6, … (59 product lines)): Fixed 300, Known Not Affected 165.
The dtls1_reassemble_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly validate fragment lengths in DTLS ClientHello messages, which allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via a long non-initial fragment.