CVE Vulnerabilities

CVE-2014-4911

Published: Jul 22, 2014 | Modified: Dec 04, 2015
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

The ssl_decrypt_buf function in library/ssl_tls.c in PolarSSL before 1.2.11 and 1.3.x before 1.3.8 allows remote attackers to cause a denial of service (crash) via vectors related to the GCM ciphersuites, as demonstrated using the Codenomicon Defensics toolkit.

Affected Software

Name Vendor Start Version End Version
Polarssl Polarssl 1.3.0 (including) 1.3.0 (including)
Polarssl Polarssl 1.3.0-alpha1 (including) 1.3.0-alpha1 (including)
Polarssl Polarssl 1.3.0-rc0 (including) 1.3.0-rc0 (including)
Polarssl Polarssl 1.3.1 (including) 1.3.1 (including)
Polarssl Polarssl 1.3.2 (including) 1.3.2 (including)
Polarssl Polarssl 1.3.3 (including) 1.3.3 (including)
Polarssl Polarssl 1.3.4 (including) 1.3.4 (including)
Polarssl Polarssl 1.3.5 (including) 1.3.5 (including)
Polarssl Polarssl 1.3.6 (including) 1.3.6 (including)
Polarssl Polarssl 1.3.7 (including) 1.3.7 (including)
Mbedtls Ubuntu upstream *
Polarssl Ubuntu lucid *
Polarssl Ubuntu precise *
Polarssl Ubuntu trusty *
Polarssl Ubuntu upstream *

References