CVE Vulnerabilities

CVE-2014-4911

Published: Jul 22, 2014 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

The ssl_decrypt_buf function in library/ssl_tls.c in PolarSSL before 1.2.11 and 1.3.x before 1.3.8 allows remote attackers to cause a denial of service (crash) via vectors related to the GCM ciphersuites, as demonstrated using the Codenomicon Defensics toolkit.

Affected Software

Name Vendor Start Version End Version
Polarssl Polarssl 1.3.0 (including) 1.3.0 (including)
Polarssl Polarssl 1.3.0-alpha1 (including) 1.3.0-alpha1 (including)
Polarssl Polarssl 1.3.0-rc0 (including) 1.3.0-rc0 (including)
Polarssl Polarssl 1.3.1 (including) 1.3.1 (including)
Polarssl Polarssl 1.3.2 (including) 1.3.2 (including)
Polarssl Polarssl 1.3.3 (including) 1.3.3 (including)
Polarssl Polarssl 1.3.4 (including) 1.3.4 (including)
Polarssl Polarssl 1.3.5 (including) 1.3.5 (including)
Polarssl Polarssl 1.3.6 (including) 1.3.6 (including)
Polarssl Polarssl 1.3.7 (including) 1.3.7 (including)
Mbedtls Ubuntu upstream *
Polarssl Ubuntu lucid *
Polarssl Ubuntu precise *
Polarssl Ubuntu trusty *
Polarssl Ubuntu upstream *

References