Lucene search

K
archlinuxArch LinuxASA-201411-4
HistoryNov 06, 2014 - 12:00 a.m.

polarssl: multiple issues

2014-11-0600:00:00
Arch Linux
lists.archlinux.org
20

EPSS

0.009

Percentile

83.0%

  • CVE-2014-8627 (weak signature negotiation)
    A mistake resulted in servers negotiating the lowest common hash from
    signature_algorithms extension in TLS 1.2.

  • CVE-2014-8628 (memory leaks)
    Two issues were found that result in remotely triggerable memory leaks
    when parsing crafted ClientHello messages or X.509 certificates.

OSVersionArchitecturePackageVersionFilename
anyanyanypolarssl< 1.3.9-1UNKNOWN