CVE-2013-4623
30.09.2013, 22:55
The x509parse_crt function in x509.h in PolarSSL 1.1.x before 1.1.7 and 1.2.x before 1.2.8 does not properly parse certificate messages during the SSL/TLS handshake, which allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a certificate message that contains a PEM encoded certificate.Enginsight
Vendor | Product | Version |
---|---|---|
polarssl | polarssl | 1.1.0 |
polarssl | polarssl | 1.1.0:rc0 |
polarssl | polarssl | 1.1.0:rc1 |
polarssl | polarssl | 1.1.1 |
polarssl | polarssl | 1.1.2 |
polarssl | polarssl | 1.1.3 |
polarssl | polarssl | 1.1.4 |
polarssl | polarssl | 1.1.5 |
polarssl | polarssl | 1.1.6 |
polarssl | polarssl | 1.2.0 |
polarssl | polarssl | 1.2.1 |
polarssl | polarssl | 1.2.2 |
polarssl | polarssl | 1.2.3 |
polarssl | polarssl | 1.2.4 |
polarssl | polarssl | 1.2.5 |
polarssl | polarssl | 1.2.6 |
polarssl | polarssl | 1.2.7 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
References