Lucene search

K
cveMitreCVE-2014-4911
HistoryJul 22, 2014 - 2:55 p.m.

CVE-2014-4911

2014-07-2214:55:09
CWE-310
mitre
web.nvd.nist.gov
40
polarssl
denial of service
cve-2014-4911
gcm ciphersuites
ssl_decrypt_buf
security vulnerability

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

AI Score

6.3

Confidence

Low

EPSS

0.004

Percentile

74.9%

The ssl_decrypt_buf function in library/ssl_tls.c in PolarSSL before 1.2.11 and 1.3.x before 1.3.8 allows remote attackers to cause a denial of service (crash) via vectors related to the GCM ciphersuites, as demonstrated using the Codenomicon Defensics toolkit.

Affected configurations

Nvd
Node
polarsslpolarsslMatch1.3.0
OR
polarsslpolarsslMatch1.3.0alpha1
OR
polarsslpolarsslMatch1.3.0rc0
OR
polarsslpolarsslMatch1.3.1
OR
polarsslpolarsslMatch1.3.2
OR
polarsslpolarsslMatch1.3.3
OR
polarsslpolarsslMatch1.3.4
OR
polarsslpolarsslMatch1.3.5
OR
polarsslpolarsslMatch1.3.6
OR
polarsslpolarsslMatch1.3.7
Node
polarsslpolarsslRange1.2.10
OR
polarsslpolarsslMatch1.2.0
OR
polarsslpolarsslMatch1.2.1
OR
polarsslpolarsslMatch1.2.2
OR
polarsslpolarsslMatch1.2.3
OR
polarsslpolarsslMatch1.2.4
OR
polarsslpolarsslMatch1.2.5
OR
polarsslpolarsslMatch1.2.6
OR
polarsslpolarsslMatch1.2.7
OR
polarsslpolarsslMatch1.2.8
OR
polarsslpolarsslMatch1.2.9
Node
debiandebian_linuxMatch6.0
OR
debiandebian_linuxMatch7.0
OR
debiandebian_linuxMatch8.0
VendorProductVersionCPE
polarsslpolarssl1.3.0cpe:2.3:a:polarssl:polarssl:1.3.0:*:*:*:*:*:*:*
polarsslpolarssl1.3.0cpe:2.3:a:polarssl:polarssl:1.3.0:alpha1:*:*:*:*:*:*
polarsslpolarssl1.3.0cpe:2.3:a:polarssl:polarssl:1.3.0:rc0:*:*:*:*:*:*
polarsslpolarssl1.3.1cpe:2.3:a:polarssl:polarssl:1.3.1:*:*:*:*:*:*:*
polarsslpolarssl1.3.2cpe:2.3:a:polarssl:polarssl:1.3.2:*:*:*:*:*:*:*
polarsslpolarssl1.3.3cpe:2.3:a:polarssl:polarssl:1.3.3:*:*:*:*:*:*:*
polarsslpolarssl1.3.4cpe:2.3:a:polarssl:polarssl:1.3.4:*:*:*:*:*:*:*
polarsslpolarssl1.3.5cpe:2.3:a:polarssl:polarssl:1.3.5:*:*:*:*:*:*:*
polarsslpolarssl1.3.6cpe:2.3:a:polarssl:polarssl:1.3.6:*:*:*:*:*:*:*
polarsslpolarssl1.3.7cpe:2.3:a:polarssl:polarssl:1.3.7:*:*:*:*:*:*:*
Rows per page:
1-10 of 241

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

AI Score

6.3

Confidence

Low

EPSS

0.004

Percentile

74.9%