CVE Vulnerabilities

CVE-2014-8627

Published: Nov 24, 2014 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

PolarSSL 1.3.8 does not properly negotiate the signature algorithm to use, which allows remote attackers to conduct downgrade attacks via unspecified vectors.

Affected Software

Name Vendor Start Version End Version
Polarssl Polarssl 1.3.8 (including) 1.3.8 (including)
Polarssl Ubuntu lucid *
Polarssl Ubuntu upstream *

References