Tenable SecurityCenter Multiple DoS (TNS-2014-11)
High Nessus Plugin ID 80303
SynopsisThe remote application is affected by multiple denial of service vulnerabilities.
DescriptionThe SecurityCenter application installed on the remote host is affected by multiple denial of service vulnerabilities in the bundled OpenSSL library. The library is version 1.0.1 prior to 1.0.1j. It is, therefore, affected by the following vulnerabilities :
- A memory leak exists in the DTLS SRTP extension parsing code. A remote attacker can exploit this issue, using a specially crafted handshake message, to cause excessive memory consumption, resulting in a denial of service condition. (CVE-2014-3513)
- A memory leak exists in the SSL, TLS, and DTLS servers related to session ticket handling. A remote attacker can exploit this, using a large number of invalid session tickets, to cause a denial of service condition.
SolutionApply the relevant patch referenced in the vendor advisory.