CVE Vulnerabilities

CVE-2011-1923

Published: Jun 20, 2012 | Modified: Oct 24, 2013
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:H/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

The Diffie-Hellman key-exchange implementation in dhm.c in PolarSSL before 0.14.2 does not properly validate a public parameter, which makes it easier for man-in-the-middle attackers to obtain the shared secret key by modifying network traffic, a related issue to CVE-2011-5095.

Affected Software

Name Vendor Start Version End Version
Polarssl Polarssl * 0.14.0 (including)
Polarssl Polarssl 0.10.0 (including) 0.10.0 (including)
Polarssl Polarssl 0.10.1 (including) 0.10.1 (including)
Polarssl Polarssl 0.11.0 (including) 0.11.0 (including)
Polarssl Polarssl 0.11.1 (including) 0.11.1 (including)
Polarssl Polarssl 0.12.0 (including) 0.12.0 (including)
Polarssl Polarssl 0.12.1 (including) 0.12.1 (including)
Polarssl Polarssl 0.13.1 (including) 0.13.1 (including)

References